March 12, 2004 7:52 AM PST

Netsky variants spark search for code

Related Stories

Netsky, we hardly knew ye

March 9, 2004

Worm authors talk trash

March 3, 2004

Second Netsky worm on the loose

February 18, 2004

No coffee, but here's another Bagle

February 17, 2004

A 20-year plague

November 25, 2003
Security experts suspect that the author of Netsky, one of the most successful pieces of malicious software this year, is distributing the worm's source code on the Internet.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


On Tuesday, the 11th incarnation of the Netsky worm was found to contain a message from its author saying there would be no more variants. However, the Netsky.K note also indicated that the worm's source code would be published, which could allow any number of people to develop their own version of Netsky. Since then, Netsky.L and Netsky.M have been discovered, and security researchers say they show signs of being written by a different author.

Mikko Hypponen, director of antivirus research at F-Secure, said that although the latest variants seem to have been written by a different person, he has not found any proof that the code is being distributed. "We haven't seen the source code in any of the typical places where we would expect to see it, but we have been talking to our informants from the underground," Hypponen said.

Graham Cluley, senior technology consultant at Sophos, said he could not confirm that the source code has been published on the Internet but suspects it is being sent to small mailing lists.

"We have no proof that the source code is out there," Cluley said, "but our suspicion is it may be available to just a small number of people because the Netsky.L and Netsky.M versions look like they have reused the source code to an extent."

Taunts absent
Until Tuesday, all of the Netsky worm variants contained text that insulted the authors of the MyDoom and Bagle worms. But the last two variants of Netsky have not included the taunts.

"We don't think they are written by the same guy because a lot of the childish banter isn't there. The anti-Bagle attack isn't there and, most importantly perhaps, the reference to Skynet, which has been included in all the other variants, isn't in there either," Cluley said. "Skynet" is the name the author gives the program, though others call it Netsky.

But Hypponen said there is a possibility that the author simply wants it to look like he is no longer creating new variants: "It looks like either this guy is releasing new versions and trying to make it look like he is not doing it," he said. "Or--and this I think is more likely--he has distributed the code to a small group and the variants are coming from there."

Even if the code is distributed, Cluley said he doesn't believe it will result in a deluge of Netsky worms. "This doesn't necessarily mean we will see a glut of new worms that will have the same impact as the original Netsky because there are lots of other virus source codes available on the Internet. But the Netsky.L and Netsky.M variants haven't spread as far as the earlier ones, possibly because the original author of Netsky had a better system for distributing the virus."

However, Hypponen acknowledges that if the source code were published, it would be popular in the malicious software community. "The source code from Netsky is hot stuff because the worm has been so successful," he said.

Munir Kotadia of ZDNet UK reported from London.

See more CNET content tagged:
Netsky virus, Graham Cluley, variant, source code, author

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Creating a 'Facebook for spies'

    The CIA, FBI, and National Security Agency are reportedly testing a social-networking site designed for use by analysts within the 16 U.S. intelligence agencies.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.