Storm worm anniversary brings fresh variants

By Tom Espiner, ZDNet UK
Monday, January 21, 2008 09:23 AM

The anniversary week of the first Storm worm attack has brought warnings of more Storm variants being sent out in spam.

The attacks are using variants of malicious code known as Troj/Dorf-AP by Sophos and Trojan.Peacomm.D by Symantec.

Sophos researchers believe the spam run is an attempt to dupe users into downloading backdoor code, which will then download further malicious code from the Internet.

The social-engineering technique attempts to trick users into clicking on a link in a "Valentine's Day" e-mail, according to a Sophos blog post.

"The body of the e-mail contains a link to an IP-address based Web site, which is actually one of the many compromised PCs in the Storm botnet," said Sophos. "The Web site displays a large red heart, while installing malware onto the visitors' PC."

Symantec researcher Hon Lau said that a spam run attempting to exploit St Valentine's Day was perhaps premature.

"I don't know about you, but I feel that this campaign has started a little bit too early," wrote Hon in a blog post. "Maybe the Peacomm creators feel that they need a head start this time, since they started a bit late on their Christmas 2007 campaign. After all they don't want to miss the boat when it comes to gathering more bots for their network."

The original Storm worm code, so named because the first spam run coincided with a severe winter storm in Europe, will reach its first anniversary on 19 January.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use SCP for quick, secure file transfers

Internet Security

When you need to securely transfer a single file, SCP may be the ideal tool.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web