By Jay Lyman TechNewsWorld Part of the ECT News Network
03/04/04 9:28 AM PT
Ken Dunham, iDefense director of malicious code, told TechNewsWorld that the variants -- which he described as trivial to create -- all are targeting easy-to-infect computers to try to outdo one another.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
Like a city corner that has fallen victim to the graffiti tag signs of rival gangs, the Internet has now become the basis of a war of words and worms between virus writers, who are unleashing virus variants to eat one another's work and spread to more computers.
The exchange among virus writers and the release of several variants taking part in the battle -- different versions of the Netsky, Bagle and Mydoom worms -- does not involve particularly damaging or malicious code, but it is causing chaos, according to virus fighters.
"The volume and rate at which these new Netsky, Bagle and Mydoom variants are surfacing is unprecedented," said an advisory earlier this week from Network Associates' (NYSE: NET) McAfee Avert. The company reported that messages in the code of the variants were directed at other virus authors, adding that some of the variants had infected at least two Fortune 500 companies.
McAfee fellow Jimmy Kuo told TechNewsWorld that with one or two variants being raised to a medium-level threat most days so far this week, the fight seems to be settling somewhat as the weekend approaches. However, Kuo indicated the spate of variants has been a burden on the security community.
"It's a huge drain on our resources and on the energy of administrators managing networks and computers and securing the Internet," Kuo said. "It's keeping us all at our terminals. It's just a very draining affair."
Turf War
Ken Dunham, iDefense director of malicious code, told TechNewsWorld that the variants -- which he described as trivial to create -- all are targeting easy-to-infect computers to try to outdo one another.
"It's interesting to note that a variant of Netsky attempts to remove a recent variant of Bagle, Bagle.C," Dunham said. "It looks like a turf war out there, with the bad guys fighting over the infected computers."
Dunham also warned that a number of the variants -- including at least six Bagle versions, two Netsky derivatives and at least one Mydoom variant -- went undetected by multiple antivirus vendors.
"There is no single magic bullet and no comprehensive patch against all of these new worms," he said.
Malware Mitigation
McAfee's Kuo said that although a few companies have been hit by the variant battle, general security rules and file blocking by large corporations have kept infections to a minimum.
Kuo said the biggest problem with virus outbreaks centers around small to medium businesses and university computing environments, many of which have reported being hit by one of the variants repeatedly this week.
Kuo added that some ISPs are filtering traffic and viruses to prevent them from reaching home users. However, he echoed Dunham's point that there are a large number of computers the virus writers know they can count on.
"What generally happens is, some people have learned and they are no longer hit by these," Kuo said. "Some people will get hit by every single one of them."
Vigilante Viruses
Although there were reports of e-mail slowdowns based on the war raging among worm variants, Kuo downplayed the effect of the struggle on the overall Internet community.
He did indicate that the worm-hunting capabilities of the latest malware -- an effort that, while not new, has been roundly rejected by the antivirus community -- represent a more general trend.
"It is a trend on the rise because virus writers have long been labeled as malicious," Kuo said. "We still believe that to be true. Now, they're trying to develop a different reputation for themselves, saying, 'We're doing this because we're trying to save the world.'"
Kuo, who said he believes the malware authors have been overtaken by their egos, also indicated the noise surrounding the variant skirmish could pave the way for a more damaging or devious worm or attack.
"They may be doing it to unload the world of various variants, but they're creating chaos and benefiting organized crime," he said. "They're making it easier [for worms] to be for spam, phishing attacks and so forth."
Juniper Founder and CTO Pradeep Sindhu on Networking the Future March 04, 2004
"The trouble with the Internet as it exists is that businesses can't take
a mission-critical application and deliver it online," Juniper CTO and founder Pradeep Sindhu told the E-Commerce Times. "The reason is that the Internet is lacking in security, reliability and quality."
Related Stories
Profile of an Internet Superhero: Inside the X-Force March 03, 2004
"We do not hire hackers. I think it's a really interesting business plan to go into the government or a bank and say you've hired a bunch of ex-hackers who will handle their security now," Dan Ingevaldson of X-Force told the E-Commerce Times. "People think hackers are the only ones who can do this stuff. They're not. Our guys are athletes. They
really know what they're doing."
New Netsky and Bagle Worms Spreading March 01, 2004
"I wouldn't be surprised if the writer [of all of the Netsky viruses] was the same person, perhaps a teenager, who is getting a kick out of all the media attention from outlets like CNN and online news magazines," Trend Micro director of antivirus research Joe Hartmann said.
MyDoom.F Spreads Carnage with Malicious Payload February 25, 2004
Among the files MyDoom.F attempts to delete are .bmp and .jpg graphic files, .avi movie files, Microsoft Word .doc files, Microsoft Excel .xls files, and Microsoft Access .mdb files. Sophos analyst Graham Cluley estimated the worm's overall success rate as averaging about 40 percent in this regard.
Netsky.B Worm Extends String of Malware Attacks February 19, 2004
Users receiving Netsky.B files on Windows machines -- regardless of mail clients -- might not have the ability to check for double extensions. If users have their machines set to hide file extensions, Windows won't show the actual executable extension, which might lead users to believe they are simply opening a text file, Forrester Research analyst Jan Sundgren told the E-Commerce Times.
Experts Warn of Worm from Windows ASN Vulnerability February 17, 2004
Ken Dunham, iDefense director of malicious code, told TechNewsWorld that the ASN vulnerability potentially could be the most widely exploited security hole of all time, saying the widespread distribution of exploit code, while not unexpected, marks another tell-tale indicator of pending trouble.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.