Spammers use YouTube to spread Storm worm

By Liam Tung, ZDNet Australia
Tuesday, August 28, 2007 11:41 AM

In yet another twist to the Storm worm menace, spammers are using a fake YouTube site to trick users into downloading malicious code which could turn their PCs into bots.

In line with the trend for virus writers to use Web sites hosting malicious code to infect vulnerable PCs, the latest effort to spread the Storm worm attempts to hijack the YouTube name to cause infections. Using a site which carries YouTube branding, those behind the attack hope to capitalize on the popularity of the video sharing Web site to trick unwary users.

Those who fall for the trick are directed to a site which includes a link to a downloadable video file carrying the Storm worm.

Using typical social engineering techniques, an e-mail containing a link to the fake YouTube site is distributed as spam, with the message: "Man you have got to tell me where you picked her up. I saw this on the Web. It has to be you. Check it out yourself at..."

F-Secure's chief research officer, Mikko Hypponen, has been monitoring the so-called Storm/Zhelatin Gang thought to be behind the worm. He recently created an online video showing how the gang uses different exploits created for vulnerabilities unique to various browsers--depending on the browser being employed, different files are sent to the user's PC.

The Storm worm was first reported in January , delivered via an executable e-mail attachment disguised as an e-greeting card. In recent months, however, spammers have changed their approach by attempting to trick users into clicking on links directing them to malware-infected sites.

Managed security vendor SecureWorks recently speculated the massive rise in occurrences of the Storm worm could be the precursor to a DoS attack on government or corporate Web sites.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Output local group membership on Windows Server

Windows Server

Command line skills for Windows Servers are essential to deliver information without wasting time. Here's how an old tool and a new tool can help.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web