ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Three-stage Bagle variants alarm experts

Matt Loney ZDNet.co.uk

Published: 02 Jun 2005 12:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest variants of the Bagle worm have alarmed antivirus vendors because of the multi-stage process they use to attack PCs.

The variants, which Computer Associates has given a new name — Glieder — because it says they are so different from previous Bagle worms, combine several elements in a way not seen before. In this staged approached, viruses seed their victims, then disarm them, and then finally exploit them.

"We've seen blended threats before where a virus uses several methods to spread," said Computer Associates Australia security architect Chris Thomas, "but not like this."

The Win32.Glieder worm spreads using a common mass-mailing method, relying on users to click on an attachment so it email itself on to names in the address book. "This is the beachhead," said Thomas. "The whole point is to get to as many victims as fast as possible with a lightweight piece of malware." On 1 June, CA saw eight variants released.

As well as mailing itself on, the mass-mailer downloads a Trojan called Win32.Fantibag to the infected machine, which is designed to block antivirus software updates. It also blocks Microsoft's update site, windowsupdate.microsoft.com, said Thomas. "This stops the machines protecting themselves," he added. "It means that software can’t get updates, that victims can't go for help and that effectively infected PC users are isolated."

The final part of the triumvirate is a second Trojan, called Win32.Mitglieder, which disables firewalls and antivirus software, further lowering the shields, and then hijacks the infected PC for use as part of a botnet. Botnets are groups of networked machines, often numbering in the thousands, that are hired as spam relays, for tracking users' behaviour and for identity theft.

"There is a commodities market for victimised PCs," said Thomas. "Recently we’ve seen spammers and criminals engaged in fraud paying approximately five cents (3p) per machine for compromised PCs."

The latest attack has been very effective. "The stats we have seen show it is still spreading quickly," said Thomas.

Thomas said the virus does not appear to block access to Computer Associates' virus patch update site, but could not offer an explanation as to why this had been missed off the list.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 141 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

PHD COMPUTER / MACHINE VISION - OXFORD

My client is seeking a PhD qualified Software Engineer with degree from a reputable University with specialist skills in the Computer / Machine ...

McAffee Anti-Virus Rollout Engineer (Field Based)

My West Midlands based client has a requirement for 2 Engineers to rollout McAfee Anti-Virus on to 600+ desktops at multiple sites throughout the ...

Commodity Quantitative Strategist - (70K+bonus) - London

If you feel you are well suited to this position, please send an up-to-date copy of your resume to Eoin ODonnell, Head of Quantitative Energy at ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment