ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hybris virus: Sleeper hit of 2001

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 12 Jan 2001 09:47 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Hybris, a computer worm that uses encrypted plug-ins to update itself, could be the sleeper hit of 2001, antivirus experts say.

"It's not a fast mailer or a mass mailer. It's slow and subtle," said Roger Thompson, technical director of malicious code research for security firm TruSecure. But "slow and steady wins the race".

The spread of most computer worms tends to spike quickly and just as quickly die out. But the 3-month-old Hybris worm shows no sign of dying anytime soon, Thompson said.

He compared the virus to Happy99.exe, also known as Win32/Ska, a malicious program that started spreading in January 1999 and remained a threat to the unwary for more than a year.

Like Happy99, the Hybris worm spreads by monitoring a PC's network connection for email messages. When a message is detected, the worm will add the addresses found in the email's header to a list. Later, Hybris selects destinations from the list to which it sends copies of itself.

Instead of the avalanche of email messages created by viruses such as Melissa and LoveLetter, Hybris produces a steady trickle of virulent email, making it less noticeable.

Another point in the worm's favor: It's written as a 32-bit Windows program, not in a scripting language as was LoveLetter or Melissa, said Vincent Gullotto, director of the anti-virus emergency research team at security firm Network Associates.

"It is a hard one to kill, like most Win32 infectors," he said. "Anything that uses Win32 infects the PC very quickly. It can infect hundreds of files in a matter of seconds."

Hybris' combination of slow spread and fast infection seems to have worked.

First detected in October 2000, the worm has remained on the top ten list of worldwide infectors, according to statistics from Trend Micro's Worldwide Virus Tracking page. For the past week, the virus has been rated as the number four most prevalent virus in the United States, as measured by the number of PCs infected, and number nine worldwide.

While Trend's statistics only take into account a small percentage of incidences worldwide, it is one of the few quantitative gauges of virus activity.

One factor that hasn't helped Hybris spread itself widely is its use of encrypted plug-ins, antivirus experts said.

Like the Babylonia, LoveLetter and MTX viruses, the Hybris virus can access information across the Internet -- in this case, from the alt.comp.virus Usenet group--and modify itself. That makes it different from the other viruses, said Nick FitzGerald, a New Zealand-based security consultant and virus researcher.

"Hybris changes shape by finding and incorporating different extensions into its code and mailing that new form to other potential victims," he said.

Typically, the antivirus community would shut down the site that hosted such plug-ins, but because their own newsgroup is being used to publish the code, they can't shut it down without hurting their own ability to fight viruses.

Antivirus experts believe the author of the virus is the same one who created the Babylonia virus, a concept virus that "phoned home" to a Japanese Web site known as the Source of Chaos and updated itself using files found on the site.

The name of the author, known as Vecna, appeared in a copyright notice in Hybris. Security firm Aladdin Knowledge Systems announced on Tuesday that they had proof that the virus had been created by the so-called VX-Brazil group. They claim that Vecna is a member of that group.

Hybris' ability to change how it works and its signature makes the worm potentially very dangerous.

Depending on which plug-ins it downloads, the worm could morph into a backdoor through a PC's security or into a malicious program that corrupts data. At present, at least eight plug-ins are known to exist.

"At some point, [the writer] could easily have control of a large number of PCs," said TruSecure's Thompson, who added that companies don't have much to worry about, as their network administrators usually update virus definitions often enough to keep up with any changes to Hybris.

Home computer users need to update their virus scanners frequently and treat email attachments with suspicion, he said.

Take me to the Virus Workshop

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
41 out of 70 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Information Analyst: Midlands. 3-6 Month Contract

The role entails in the main dealing with ad hoc requests for information, assisting and maintaining web-based statistics development, analysing ...

Information Analyst required

Information/Analyst role - Experience of statistical techniques - Significant experience working on Data Analysis or statistics - NHS or Health ...

Implementation Consultant - Calypso or Murex experts required !!

Leading Investment banking consultancy is currently looking for a specialist implementation consultant to join their growing specialist department. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments