New Netsky worm points to South Korea

Antivirus researchers have discovered a new version of the Netsky worm that contains text linking it to the SoonChunHyang University in Bucheon, South Korea.

Mikko Hyppönen, director of antivirus research at European antivirus firm F-Secure, said the latest variant contains two hidden strings: "SoonChunHyang" and "Bucheon".

"There's a University called SoonChunHyang in the city of Bucheon, South Korea. So I guess this variant has something to do with South Korea," Hyppönen said.

The original Netsky was written by Sven Jaschan, who was said to be responsible for 70 percent of all virus infections in the first half of this year, according to antivirus firm Sophos.

However Jaschan was taken into custody in May by the police in Germany who said that he had admitted programming both the Netsky and Sasser worms. During the five months preceding his arrest, there were at least 25 variants of Netsky and one of the port-scanning network worm Sasser.

Shortly before his arrest, Jaschan said he had distributed the worm's source code, which could allow any number of people to develop their own versions of the worm.

At the time, Hyppönen said that if the source code were to be published it would be very popular.

-The source code from Netsky is hot stuff because the worm has been so successful," Hyppönen said.

Since Jaschan's arrest at least another 20 variants of Netsky have been found.

Hyppönen believes all the recent Netsky variants have been created by copycats.

"As the author of the original Netsky family is out of business, these recent Netskys all seem to be hacks made by third parties," Hyppönen said.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Is green IT a marketing fad?
    It seems that green IT has dropped off the radar, with other technology issues moving to the fore. But was green IT ever a real technology movement, or was it just a marketing fad?
  • Array Gutless studios have the wrong target
    I have one word for the Australian Federation Against Copyright Theft (AFACT). Gutless.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • More blogs »

Tags

Back to top

Featured