Advertisement
Promo

Security threats Toolkit

New Netsky variant appears from Korea

Munir Kotadia ZDNet Australia

Published: 22 Oct 2004 11:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus researchers have discovered a new version of the Netsky worm that contains text linking it to the SoonChunHyang University in Bucheon, South Korea.

Mikko Hyppönen, director of antivirus research at European antivirus firm F-Secure, said the latest variant contains two hidden strings: "SoonChunHyang" and "Bucheon".

"There's a University called SoonChunHyang in the city of Bucheon, South Korea. So I guess this variant has something to do with South Korea," Hyppönen said.

The original Netsky was written by Sven Jaschan, who was said to be responsible for 70 percent of all virus infections in the first half of this year, according to antivirus firm Sophos.

However Jaschan was taken into custody in May by the police in Germany who said that he had admitted programming both the Netsky and Sasser worms. During the five months preceding his arrest, there were at least 25 variants of Netsky and one of the port-scanning network worm Sasser.

Shortly before his arrest, Jaschan said he had distributed the worm's source code, which could allow any number of people to develop their own versions of the worm.

At the time, Hyppönen said that if the source code were to be published it would be very popular.

"The source code from Netsky is hot stuff because the worm has been so successful," Hyppönen said.

Since Jaschan’s arrest at least another 20 variants of Netsky have been found.

Hyppönen believes all the recent Netsky variants have been created by copycats.

"As the author of the original Netsky family is out of business, these recent Netskys all seem to be hacks made by third parties," Hyppönen said.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here..

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
77 out of 165 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters