Advertisement
Promo

Security threats Toolkit

Symantec: Storm worm changes tack

Tom Espiner ZDNet.co.uk

Published: 02 Nov 2007 17:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Storm worm has evolved again, researchers from Symantec claim.

To streamline the worm and make it more stable, the malware authors have shed key functionalities in the malicious code, said the researchers.

The worm no longer infects other legitimate drivers on the system, instead relying on its own proprietary components to "do its dirty work". It also no longer injects itself into processes such as Explorer.exe, according to a blog post by Symantec security researcher Thomas Parsons.

"The sustained development of the Storm worm (incorporating review cycles) indicates that we will continue to see solid infection rates going forward," wrote Parsons. "So, unlike the natural phenomenon, this storm continues to huff and puff and it doesn't look like it is petering out anytime soon."

The Storm botnet was initially created at the beginning of 2007, when the Storm worm was sent out via spam, hiding in email attachments with a subject line of "230 dead as storm batters Europe".

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 13 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters