Advertisement
Promo

Security threats Toolkit

Storm Worm variant sneaks into blogs

Dawn Kawamoto CNET News

Published: 28 Feb 2007 10:23 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A variant of the Trojan horse attacks known as Storm Worm emerged Monday, targeting people who post blogs and notices to bulletin boards.

Storm Worm emerged in January and raged across the globe in the form of emails with attachments that, when opened, loaded malicious software onto victims' PCs, commandeering the machines so they could be used for further attacks.

The new Storm Worm variant attacks the machines of unsuspecting users when they open an email attachment, click on a malicious email link or visit a malicious site, said Dmitri Alperovitch, principal research scientist at Secure Computing.

But the twist comes when these people later post blogs or bulletin board notices. The software will insert into each of their postings a link to a malicious website, said Alperovitch, who rates the threat as "high".

"We haven't seen the web channel used before," he said. "In the past, we've seen malicious links distributed to people in a user's address book and made to look like it's an instant message coming from them."

The danger in this most recent case, he added, is that the user is posting a legitimate blog or bulletin board notice, unaware that a malicious link has been slipped into the text of the posting.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
17 out of 17 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters