German hate-spam spread by Sober virus



Another variant of the Sober virus, which spreads hate messages in German and English, appeared over the weekend. Security firms are warning that they have received hundreds of thousands of e-mails generated by Sober.Q in its first 24 hours.

Sober is usually a mass-mailing worm that sends a copy of itself to e-mail addresses stored on an infected computer's hard drive. However, in the same week that Germany and Europe celebrate the 60th anniversary of the end of World War II in Europe, the latest variant's sole purpose seems to be to distribute hate mail.

Scott Chasin, chief technology officer at e-mail security specialists MX Logic, said the latest variant of Sober was being uploaded to computers infected by previous variants of Sober, which meant the virus authors may have remote control over thousands of PCss.

"Sober.Q appears to be downloaded by machines infected by Sober.P... If this is the case, the Sober.P author or authors could have remote command-and-control capabilities over a large network of infected machines. This network would provide not only a megaphone to distribute messages of hate, but a platform for future spam, worm and denial of service attacks,' said Chasin.

Although spam usually tries to advertise products, Chasin said it is now also being used for spreading propaganda.

"Spam has been traditionally regarded as annoying messages that promote Viagra, porn and low cost mortgages... But for the past year we have seen a trend in which worm authors are using spam not to hawk goods, but as a tool for political propaganda," said Chasin.

Last week, antivirus firms warned that the previous Sober variant, which was disguised as winning tickets to the Soccer World Cup in 2006, had suddenly modified its behaviour and stopped propagating. The temporary lull in activity seemed to have been planned by the virus writers in preparation for this latest attack.

MX Logic's Threat Centre has reported seeing more than 125,000 instances of the Sober.Q worm and categorised it as a high severity threat. Internet security firm SurfControl reported seeing 1,000 spam e-mails within hours of the initial outbreak, which the company said is around 40 times the usual number.

Advertisement

Talkback 2 comments

    This propaganda crap has got to stop. I have both Norton and Trend Micro anti virus programs and neither one picked up on this. Is this common? I can pretty much trace the infected computers and the e-mail addresses match a lot of those at my last office Anonymous -- 19/05/05

    This propaganda crap has got to stop. I have both Norton and Trend Micro anti virus programs and neither one picked up on this. Is this common? I can pretty much trace the infected computers and the e-mail addresses match a lot of those at my last office of real estate where I worked for two years. We had those 'know it alls' that downloaded anything and everything that came along. You could actually see the performance of the machines going down. I use a laptop for work, and when I saw what was going on, I stopped going on line from our cable to the office. Is there a program or software out there that can stop all this from happening? I'd like to know---JC

    Several yahoo groups got hit by this in the last few days. In researching it, only the AVG from Grisoft seemed to be right on top of the Sober.Q variant. Others were only up to N or P. Symantec still doesn't have it listed as a current threat. MAnonymous -- 22/05/05

    Several yahoo groups got hit by this in the last few days. In researching it, only the AVG from Grisoft seemed to be right on top of the Sober.Q variant. Others were only up to N or P.
    Symantec still doesn't have it listed as a current threat.
    My own address got s****ed in the yahoo groups. My usual computer is Macintosh so I knew I wasn't infected but now I'm more sure of the PC as am running AVG on that one.
    As seen in many of the articles, the tricky part about this one is that since it doesn't actually contain a virus itself, it isn't caught by the usual virus software. I think that's how it got in the high-traffic yahoo groups. Lower membership groups didn't seem to be affected, but even moderated groups were.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured