ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Thanksgiving will bring a Sober hangover

Tom Espiner ZDNet.co.uk

Published: 25 Nov 2005 17:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest outbreak of the Sober worm will accelerate as US computer users turns the PCs back on after the Thanksgiving holiday, security firm MessageLabs warned on Friday.

Business users will return from the break and open mail that has been sitting in their inbox since the first hours of the attack, which could include infected emails, MessageLabs warned.

Sober-Y spreads in emails that pretend to come from the FBI or which claim to contain video clips of celebrity heiress Paris Hilton. It is activated if the user runs an email attachment.

"Once this worm has been activated behind a firewall, it's very difficult to identify, as most firewalls don't inspect outbound data traffic." said Paul Wood, senior analyst at MessageLabs.

Businesses may also be suffer if their mail servers are swamped by email traffic caused by infected home users.

"Businesses may suffer collateral damage due to the volume of mail hitting people's mailservers. Even secure business servers may be affected, as spam still consumes bandwidth before it can be rejected," said Wood.

This week's Sober attack is the largest that MessageLabs has seen in 2005. "This is the biggest outbreak of a mass-mailing virus all year. It is a concern because we thought we'd seen the last of mass-mailers," said Wood.

Experts at antivirus company Sophos also see Sober-Y as a major threat. Globally, one in 18 emails are now infected by the Sober worm, Sophos said on Friday.

"The new Sober worm is spreading at such a rate that it now accounts for over 80 percent of all viruses reported. It is currently the most widespread computer virus in the world," said Graham Cluley, Sophos' senior technology analyst.

If activated, Sober-Y attempts to turn off security software on the user's computer. The zip file in the attachment contains a copy of the worm with the filename File-packed_dataInfo.exe. The worm then scans the user's hard drive for other email addresses, in its search for other computers to infect, Sophos said.

MessageLabs believes Sober-Y could continue to spread in large quantities for some time, as the auto switch-off function used in most mass-mailing malware hasn't been enabled.

"Normally you would see an auto switch-off function included in the code, because controllers don't want to draw too much attention to their botnets — so there's a cut-off date, and the outbreak stops. We haven't seen a cut-off date in this Trojan, so this outbreak could continue for some time," said Wood.

This outbreak is likely to be financially motivated. MessageLabs believes that cybercriminals may be trying to increase the number of compromised computers they have access to before Christmas, for financial gains.

"We believe botnet controllers are bolstering their botnets before Christmas, to sell access to spammers," said Wood.

The source code for Sober originated in Germany, but is now being used by Eastern European criminal gangs, said MessageLabs.

IT managers were advised to actively monitor their outbound email traffic for evidence that they have been infected by Sober-Y, and not just rely on a firewall. "It's certainly a challenge for organisations to control email traffic just by using a firewall. IT managers can manage this particular outbreak by protecting HTTP and SMTP traffic," said Wood.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
52 out of 143 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Power Supply Design Engineer Needed ASAP/ SMPS/ London

We are looking for a senior power supply engineer for design of switch mode power electronics for A range of bluer chip clients primarily in the ...

Software Engineer

NATS provides air traffic control services to aircraft flying in UK airspace, and over the eastern part of the North Atlantic. Needless to say, this ...

Juniper Sales Professional, JUNOS, NetScreen, Firewall, WX, London

Juniper Sales Professional required for pivotal role within a global provider of security & network infrastructure services & products based in ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation