Advertisement
Promo

Security threats Toolkit

PayPal users targeted by latest Mimail mutant

Munir Kotadia ZDNet.co.uk

Published: 18 Nov 2003 14:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Just days after being hit by the Mimail.i worm, PayPal users are now under attack from Mimail.j, which is spreading rapidly.

In the past day, around 25,000 users have been infected by Mimail.j, the latest mass-mailing worm designed to target PayPal users. According to security company F-Secure, Mimail.j is almost identical to Mimail.i but seems to be spreading more quickly than its predecessor. The latest variant of Mimail appears to be sent from "Do_Not_Reply@paypal.com" and contains a string of random characters in the subject line. Attached to the email is either a file called "InfoUpdate.exe" or "www.paypal.com.pif".

Click here for more details about the worm and how to remove it.

Mark Sunner, chief technology officer at email security firm MessageLabs, said that Mimail.j's sole purpose is to defraud unsuspecting users, which he believes indicates a change in the mindset of virus authors: "Once, disruption was motivation enough, but now we are seeing a new breed of cybercriminal that is intent on using viruses as a means of lining their own pockets. They rely on duping a crop of unsuspecting users before a new variant is released and the process begins again," he said.

"It is curious that two have come along in the space of three or four days but Mimail.j is a recompiled version of Mimail.i, with minimal changes. Most of the changes seem to reflect different subject lines and different email content text when users open it, but the method of operating is pretty identical," said a spokesman for F-Secure.

The worm has been rated highly dangerous because of the risk it carries for PayPal users: "Someone has gone to a considerable amount of trouble to fashion PayPal-lookalike screens and 'phish' for credit card details," said the F-Secure spokesman.

The recent spate of worm and virus attacks has led network giant Cisco to collaborate with antivirus software vendors -- including Network Associates, Symantec, and Trend Micro --  to create the Cisco Network Admission Control system, which is part of the company's strategy to help enterprises minimising the impact of viruses and worms.

Mark Bouchard, senior programme director at the META Group, welcomed the Cisco announcement, and commented that enterprises should make it a priority to ensure that insecure nodes within their network are adequately protected: "Many organisations were successful at stopping recent worm attacks at their Internet boundaries, yet still fell victim to the exploits when mobile or guest users connected their infected PCs directly to internal local area networks. Eliminating this type of threat will require a combination of strengthened policies and network admission control systems."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
56 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters