Advertisement
Promo

Security threats Toolkit

Bagle and Mytob evolve again

Joris Evers CNET News

Published: 01 Jun 2005 09:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A bunch of new variants of the Bagle virus and Mytob worm are spreading, but they won't pose a major threat if people take the usual precautions, security companies say.

Three new iterations of Bagle, released at one-hour intervals, popped up on Tuesday, said Maksym Schipka, a senior antivirus researcher at MessageLabs. About 70 variants of the mass-mailing computer virus have been reported since it first appeared in January 2004.

MessageLabs, which filters out malicious software from email for clients, stopped nearly 100,000 copies of the Bagle variants in the first few hours after they hit, Schipka said. "We are seeing huge volumes," he said. MessageLabs said that the new versions appear to have originated from a Yahoo group.

The new Bagles do little to trick users into running their malicious content. The email has no subject line or body text. The attachment is a ZIP archive that will attempt to download a Trojan horse from a list of Web sites, if unpacked and run. The Trojan harvests email addresses from the PC to further spread the virus, Schipka said. It also installs a backdoor.

Mytob, like Bagle, is generating new offspring. It is a malicious worm that installs a backdoor and uses its own email engine to forward itself to addresses that it gathers from infected computers.

Two new variants of Mytob have appeared over the past few days — one on Sunday and one on Tuesday, said Craig Schmugar, a virus research manager at McAfee.

New versions of Bagle and Mytob appear often. These recent ones are more of the same, said Alfred Huger, senior director of engineering at Symantec Security Response. "They are both, thankfully, fairly low-risk threats at this stage, in terms of their spread. We're seeing a low number of infections."

PC users can protect themselves by installing the latest updates for their antivirus software and using caution when opening email attachments, the security providers said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
62 out of 114 people found this useful



Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters