"Storm worm," one of the larger Trojan horse attacks in recent years, is baiting people with timely information about a deadly, real-life storm front, security researchers said Friday.
People who open the attachment then unknowingly become part of a botnet. A botnet serves as an army of commandeered computers, which are later used by attackers without their owners' knowledge.
Storm worm carries the subject line "230 dead as storm batters Europe," Hypponen said, noting the unusual twist to the e-mail.
"The e-mail was started 15 hours ago, when the storm was peaking in Central Europe," Hypponen said. "This is unusual in that it was very timely."
Storm worm is a Trojan horse with an executable file as an attachment. Cybercriminals took advantage of social engineering, using the news of the European storm to get people to open the attached malicious file, which promises more news on the weather emergency. The recipient must open the file for it to execute.
The file creates a back door to a computer that can be exploited later to steal data or to use the computer to post spam.
Storm worm is already close to being as large as the bigger attacks of 2006, Hypponen said, though it's still smaller than Sasser and Slammer.
Hypponen also noted that this Trojan horse is unusual because most attacks these days tend to be smaller and targeted, as criminals seek to pilfer personal information for financial gain, rather than fame.
Though Storm worm is widespread, the damage may ultimately be minimal in the U.S. because most tech security companies will have already added it to their blocking list before people get into work, he added.
Other e-mail subject lines for it include "U.S. Secretary of State Condoleezza..." and "A killer at 11, he's free at 21 and..."
Every article about any type of virus or security, we get people that come on and claim that OSX is the most secure OS ever in the history of man. Thanks for the info
I have not heard of any viruses for the Timex 360 and not one virus has hit this platform in at least a decade....
Mac folks should be happy that most attackers still hate the other guy so much they do not spend much time looking at their platform. Have the common sense to know when not to tease. All platforms have weakness. You really do not want to be proven wrong.
Yet another virus that I probably won't get. The last virus I got was a DOS virus in the late 80s.
It's hardly just the OS. The OS matters but not as much as people. Put MAC and LINUX boxes on the desktop, in the hands of similar users and desktop support groups and you'll get the same results.
All this talk about writing a Mac virus and getting bragging rights ignores the main reason for viruses and worms these days...money! In the old days it was about who could write the coolest, fastest, most-targeted. Now it's about creating spam-bot networks to sell to as a service to spammers.
Read the article and it's obvious. How could a worm get sent to hurdreds of thousands of people (the intent) if it targeted an OS used by 10% of users. It ain't about props any more, it's about cash!
If as you say, and I agree, the main reason to spread viruses these days is "about cash", why aren't these virus writers targeting Macs?
"Those who surf the Web using a Mac tend to be better educated and make more money than their PC-using counterparts, according to a report from Nielsen/NetRatings."
Once again, a story about an email worm which only affects one vendor's system fails to mention that vendor. Doesn't even mention the fact that it only hits one vendor's OS.
Don't you think that was a relevant detail? Why do you think it was left out?
The night after the Melissa worm hit, Ted Koppel had a real expert on his show, who explained in language anyone could understand exactly why the worm got so far so fast. It was a career-limiting move for Koppel. _Nightline_ doesn't do malware stories any more.
I worked on the biggest selling 10BASE-T card in the industry's history. We were the first with Linux support, and the default NIC in Linux kernels for years. Before I left, I asked our CEO why we never mentioned "works with Linux" on the retail box. He said he couldn't risk getting the 800 pound gorilla angry. The gorilla is irritable. Everybody in that business is afraid, and that includes the pundits and publishers.
Do you have a legitimate reason for not providing information about the operating system this worm uses to propagate itself? Are we to assume this worm affects ALL operating systems and users or just one. On the surface it seems to you are deliberately obfuscating the problem and don't want people to know what system is affected. Is it C|net policy to protect the identity of a certain operating system when it is the cause of a threat?"
>>>People who open the attachment then unknowingly become part of a botnet.<<<
Internet Common Sense 101: Don't click on unknown URL links or unknown attachments... ESPECIALLY if they're of the executable type, and ALSO especially if they're from an unknown spoofed source.
If you don't know how to tell the difference, then give up computing or learn how to tell the difference.
Doesn't really matter what OS the worm is after!!!
Internet Common Sense 101 is Internet Common Sense 101.
They would have to be morons NOT to write code that would affect 90% of computers. You would BE a moron if you think OSX does not have holes. They just are ignored for the most part.
Web giant is spending $120 million to beef up its Mountain View, Calif., headquarters, according to filings with the city reviewed by the San Jose Mercury News.
Tor's "obfsproxy" technology would make encrypted data look innocuous and let it dodge government censors. That could help citizens in Iran reach blocked sites as antigovernment protests reportedly loom.
MIT creates a simulation to celebrate the 50th anniversary of Spacewar. A relic of the early days of minicomputers, it was one of the first computer video games and set the stage for many others, including Asteroids.
George Lucas has just released his version of "Star Wars" in 3D, but c'mon--the guy believes Greedo shot first. Why not make your own Star Wars world? In the first installment of a Crave series, a crack team of crafters fight the power and turn paper bags into the Rebel Alliance's Admiral Ackbar. It's a sack!
choice.
Mac folks should be happy that most attackers still hate the other guy so much they do not spend much time looking at their platform. Have the common sense to know when not to tease. All platforms have weakness. You really do not want to be proven wrong.
It's hardly just the OS. The OS matters but not as much as people. Put MAC and LINUX boxes on the desktop, in the hands of similar users and desktop support groups and you'll get the same results.
Read the article and it's obvious. How could a worm get sent to hurdreds of thousands of people (the intent) if it targeted an OS used by 10% of users. It ain't about props any more, it's about cash!
"Those who surf the Web using a Mac tend to be better educated and make more money than their PC-using counterparts, according to a report from Nielsen/NetRatings."
<a class="jive-link-external" href="http://news.com.com/2100-1040-943519.html" target="_newWindow">http://news.com.com/2100-1040-943519.html</a>
Switching to a Mac last year was the smartest move I ever made..!!
every thread. every god damn time. you have a mac, get over it. so do i, but i seem to have something that's rare amongst mac users.
it's called modesty, with a dash of manners.
Don't you think that was a relevant detail? Why do you think it was left out?
The night after the Melissa worm hit, Ted Koppel had a real expert on his show, who explained in language anyone could understand exactly why the worm got so far so fast. It was a career-limiting move for Koppel. _Nightline_ doesn't do malware stories any more.
I worked on the biggest selling 10BASE-T card in the industry's history. We were the first with Linux support, and the default NIC in Linux kernels for years. Before I left, I asked our CEO why we never mentioned "works with Linux" on the retail box. He said he couldn't risk getting the 800 pound gorilla angry. The gorilla is irritable. Everybody in that business is afraid, and that includes the pundits and publishers.
<a class="jive-link-external" href="http://notwindoze.blogspot.com" target="_newWindow">http://notwindoze.blogspot.com</a>
NO CIGAR
Do you have a legitimate reason for not providing information
about the operating system this worm uses to propagate itself?
Are we to assume this worm affects ALL operating systems and
users or just one. On the surface it seems to you are deliberately
obfuscating the problem and don't want people to know what
system is affected. Is it C|net policy to protect the identity of a
certain operating system when it is the cause of a threat?"
Internet Common Sense 101: Don't click on unknown URL links or unknown attachments... ESPECIALLY if they're of the executable type, and ALSO especially if they're from an unknown spoofed source.
If you don't know how to tell the difference, then give up computing or learn how to tell the difference.
Doesn't really matter what OS the worm is after!!!
Internet Common Sense 101 is Internet Common Sense 101.
Adhere to it or get infected!!!
Walt