Does a virus gang own the Internet?

commentary Who knows what the authors of Netsky and Sasser are thinking. Robert Vamosi offers some speculation based on messages left inside recent viruses by the authors themselves.

After a major virus or worm outbreak like Sasser, I'm frequently asked, "Who are these people?" or, "What are they doing, releasing these viruses?" To answer, I point to Clive Thompson's in-depth article for the New York Times Magazine profiling groups of young virus writers who create viral code for fun and games. It now appears that one gang of virus writers is behind Sasser -- and the nearly 30 variations of Netsky we've seen since February.

I'm not saying that the specific individuals profiled in Thompson's piece are those responsible for Sasser; still, his article gives some perspective on the underlying mentality. Like their urban gang counterparts, virus gangs are interested in marking territory on the Internet and showing off their elite skills. For example, Skynet, the gang I believe is behind Sasser and Netsky, doesn't use IRC chat rooms to communicate. That would be too easy. Instead, members of Skynet use messages within their own viral creations.

Programmers often leave plain-text statements within their code. From statements found embedded within recent viruses, we know that there's been a turf battle raging since February between Skynet, the viral authors of Bagle, and the viral authors using the publicly available MyDoom source code. From Netsky.c: "We are the skynet--you can't hide yourself---we kill malware...MyDoom.f is a thief of our idea!" To which the author of MyDoom.g responded: "Hey, NetSky...Don't ruin our business, wanna start a war?" Mostly the messages have been little more than taunts, and these taunts have even extended to antivirus vendors themselves.

To advance their dialogue, the Skynet and Bagle virus gangs have been hammering out competing viral code every couple of days. Thus, both Netsky and Bagle have depleted the 26 letters of the alphabet and are now into double letters, producing variations known as Bagle.aa and Netsky.ac. Most of these variations have been little more than background noise on the Internet, but some, such as Netsky.p, have been very successful, rising to the level of a medium threat.

Like their urban gang counterparts, virus gangs are interested in marking territory on the Internet and showing off their elite skills.
By piecing together the viral messages, it's possible to get a sense of what's going on behind the virus. Within Netsky.ac: "Hey, av [antivirus] firms, do you know that we have programmed the sasser virus?!? Yeah thats true! Why do you have named it sasser? A Tip: Compare the FTP-Server code with the one from Skynet.V!!! LooL! We are the Skynet." As proof, the authors supplied a snippet of the Sasser source code. Since the Sasser code isn't available on the Internet, inclusion of the code more or less links the authors of Netsky to Sasser.

Further analysis provided by antivirus researcher Mikko Hipponen of F-Secure also finds programming similarities between Sasser and Netsky. While it's possible two different programmers coded these, the order of the procedure calls and the overall structure of the two programs suggest a common point of origin.

A complete study of Sasser variations a through d has been published by the security company Lurhq, showing that if the authors of Netsky are responsible for Sasser, there are as many differences as similarities. While Netsky tries to open back doors on infected computers, and these compromised machines are ostensibly sold to spammers to relay their wares, Sasser does no such thing. Sasser isn't malicious; it's much more of an annoyance. So what's its point?

I think the Skynet gang is simply marking territory. Since the Microsoft patch MS04-011 (the recommended remedy for Sasser infections) fixes up to 14 specific vulnerabilities, the authors of Sasser have effectively blocked others from creating a major virus or worm that exploits flaws in SSL or ANS.1, for which exploits already exist. While Sasser doesn't completely rule out someone creating a worm or a virus that exploits those flaws, this worm makes it less likely because the number of patched systems has gone up exponentially since May 1, 2004.

Should we thank Skynet for releasing a relatively benign worm that got everyone to patch their systems in advance of something even worse? No. In my mind, the members of Skynet are still thugs.

By putting a firewall on your desktop, by updating your PC with the latest Microsoft updates, you can prevent Skynet and other viral gangs from claiming bragging rights. By succeeding in getting everyone to secure their PCs, I think Skynet and others will ultimately fail.

Advertisement

Talkback 2 comments

    > By succeeding in getting ...Anonymous -- 11/05/04

    > By succeeding in getting everyone to secure
    > their PCs, I think Skynet and others will
    > ultimately fail.

    My thoughts:
    They'll keep winning as long as there is pathetic QA testing within Microsoft. If Microsoft increased their QA testing and produced flawless code, then the likes of Skynet might start failing. They will, however, never stop.

    own the internet? Hrrm. I thin ...Anonymous -- 11/05/04

    own the internet?
    Hrrm. I think there was too much drivel in
    this article. And the judgement call at the end?

    I think the author's reasoning for making the decision that virus writers are "thugs" should be
    made clear. Is it not better to get infected with a less malicious virus? Of COURSE it is. His evidence of turf wars is still pretty scant, even though the premise of preventing massive attacks based on MS security goofs-in-progress is interesting. This premise is flawed because I don't see evidence that these virus writers, known only by short remarks in thier code, and compared with some "virus writers" in a NY times article, are that organized. I want them caught if possible, and for folks to get to the bottom of it.
    Unfortunately, while there are MS products and others on the internet unpatched, there is plenty of room for these guys to play and play and play forget about turf wars and organized crime until some evidence surfaces.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured