Advertisement
Promo

Security threats Toolkit

Beware the 'Happy New Year' worm

Marguerite Reardon CNET News

Published: 02 Jan 2007 08:57 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An email worm disguised as a New Year's greeting is making the rounds on the internet.

Worm-laden messages are titled "Happy New Year" and contain an attachment called either postcard.exe or postcard.zip, according to experts at VeriSign's iDefense Labs, which provides information on security flaws and exploits. If the attachment is opened, malicious software is downloaded from the internet and can infect computers running Windows operating systems.

Once a computer is infected, it looks for open mail proxies and begins spamming mail to infect other computers. The worm is already moving quickly across the internet, at a rate of five emails per second on at least one large network, according to the iDefense Labs website.

Security experts say that although the virus looks similar to the Warezov Trojan horse that has plagued the internet for the past month, it is actually a new variant of the worm and has been largely undetected as of 28 December. iDefense performed a triage analysis of the threat and found that more than a dozen codes were installed on a computer from several worm and Trojan horse families. More than 160 email servers are used by the worm to send out spam to potential victims, the company said.

High volumes of mass emails are usually sent around the Christmas period. This year has been no different, experts say. The spike in spam is largely attributed to the fact that people have been more likely to open the messages.

Consumers have been shopping online more, desperate for gift ideas. They have also been expecting electronic greeting cards from friends and family. Malicious spammers have been able to exploit this expectation by designing Trojan horses that can fool unsuspecting users.

Antivirus software maker McAfee issued several advisories over the Christmas break, warning customers to be wary of such Trojans. On Wednesday, it cautioned users about a malicious email attachment named Christmas+Blessing-4.ppt that installs software enabling attackers to remotely access a compromised computer.

Like many Trojans, the "Happy New Year" worm is not recognised by all virus scanners, so users should be extremely cautious when opening email attachments, experts say.

"Everyone should be on guard for emails and other content potentially harbouring malicious code during the holiday period", said Ken Dunham, director of the Rapid Response Team at iDefense Labs.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
239 out of 308 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters