Storm worm celebrates first birthday with love

By Tom Espiner, ZDNet UK
21 January 2008 09:21 AM
Tags: bank, fraud, phishing, storm worm, spam, valentine, variant, sopho

The anniversary week of the first Storm worm attack brought more variants, one of which launches an early Valentine Day attack.

The social-engineering technique attempts to trick users into clicking on a link in a "Valentine's Day" e-mail, according to Sophos.

"The body of the e-mail contains a link to an IP-address based Web site, which is actually one of the many compromised PCs in the Storm botnet," said Sophos. "The Web site displays a large red heart, while installing malware onto the vistors' PC."

Symantec researcher Hon Lau said that a spam run attempting to exploit St Valentine's Day was perhaps premature.

"I don't know about you, but I feel that this campaign has started a little bit too early," wrote Hon in a blog post. "Maybe the Peacomm creators feel that they need a head start this time, since they started a bit late on their Christmas 2007 campaign. After all they don't want to miss the boat when it comes to gathering more bots for their network."

The most recent attacks are using variants of malicious code known as Troj/Dorf-AP by Sophos and Trojan.Peacomm.D by Symantec.

The original Storm worm code, so named because the first spam run coincided with a severe winter storm in Europe, will reach its first anniversary on 19 January.

Advertisement

Talkback 0 comments

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured