By Erika Morphy TechNewsWorld Part of the ECT News Network
11/21/06 3:50 PM PT
A self-replicating worm dubbed "Grey Goo" forced the shutdown of the virtual community Second Life after the worm's creators claimed to spin rings of gold, duping players who interacted with it into spreading the malware throughout the virtual environment. "The worm dropped into Second Life is a 'Grief Bomb,'" Rob Enderle, principal analyst at the Enderle Group, told TechNewsWorld.
Talk about art imitating life. A self-replicating worm dubbed "Grey Goo" has caused the virtual community Second Life to shut down at least once, according to the site's owners, Linden Life. Within the Second Life virtual environment, Grey Goo's creators claimed to spin gold rings, and unwitting players interacted with them to spread the malware further.
"This was basically a proof-of-concept worm that only self-replicated using the scripting features inside Second Life," explained Stefan Savage, a professor of Computer Science and Engineering at UC San Diego and a computer security/worm/virus expert. "They have filters that try to prevent this kind of self-replication, but evidently the author found a hole in them," he told TechNewsWorld.
A 'Grief Bomb'
Given that it only affected Second Life users' game time, it was not as destructive as some worms have been. Also, Grey Goo does not appear to have been financially motivated -- that is, it didn't try to phish or otherwise steal personal financial data from users. Nonetheless, players were rattled by the interruption -- which was likely the whole point, says Rob Enderle, principal analyst at the Enderle Group.
"The worm dropped into Second Life is a 'Grief Bomb.' This kind of an attack's sole purpose is to mess up the game" and get those that play and maintain it upset, Enderle told TechNewsWorld.
Targeting Web 2.0
Even though it was a relatively benign occurrence as worms go, Grey Goo is worth noting, as it may be only the first of this type of malware to come, warned Roger Thompson, CTO of anti-exploit software vendor Exploit Prevention Labs. "Increasingly, as we move [toward] Web 2.0, [and] with applications like MySpace or YouTube becoming commonplace, I think we will see more worms targeting these communities," he told TechNewsWorld.
Until the next YouTube or MySpace becomes apparent, however, virus writers are likely to focus on virtual communities like Second Life. If the real world is any guide, a proof-of-concept worm is likely to be followed with one that has a genuine payload.
Users of these virtual communities should start taking the necessary precautions if they haven't been already, Randy Abrams, director of Technical Education, ESET, told TechNewsWorld.
The Payload Next Time
"Second Life may be a virtual world, but real dollars are being exchanged. This creates some pretty strong motivations. In the case of Grey Goo, theft doesn't appear to be a motivation. However ... it would have been fairly easy to add a payload if the author had so desired," he said.
The worm's appearance shouldn't have been a surprise, Rob Graham, CEO of Errata Security added, as most popular online games have had similar worm-replication problems.
"One exception is the game 'World of Warcraft,'" he told TechNewsWorld. "It's not because they have smarter programmers, but because its creator had already been burned by replication bugs in its previous game called 'Diablo.'"
Programmers in the gaming industry are still coding in a negligent manner, Graham concluded. "We will continue to see such problems in online games in the coming years."
Nintendo's Wii: Can It Compete? November 20, 2006
Nintendo launched its new Wii game console this weekend, but whether it's sufficiently armed to compete with Sony's Playstation 3 and Microsoft's Xbox is still an open question. The Wii's major distinction -- its innovative remote controller -- is an intriguing offering. However, the Wii "is not a groundbreaking development" overall, Yankee Group analyst Mike Goodman said.
Related Stories
Google Apologizes for Virus Distribution November 10, 2006
Google acknowledged that it inadvertently e-mailed postings to some 50,000 users that contained the Kama Sutra virus. The search giant revealed the mix-up in a posting to its Video Blog site. "We're sorry for any inconvenience, and we're taking steps to ensure that this doesn't happen again," the message said.
Apple Ships iPods With Windows Virus October 18, 2006
Apple on Tuesday said a small number of Video iPods produced after Sept. 12, 2006, are harboring a Windows virus known as RavMonE. Apple said there have been fewer than 25 reports of the issue, which does not affect other models of the MP3 player or its Macintosh computers.
Survey Finds Consumers Balk at Updating Malware Protection July 19, 2006
"Overall, the research shows that many consumers have a false sense of security while online," ESET Chief Research Officer Andrew Lee said in a statement. "With the number of zero-day threats rapidly increasing, users need to be even more cautious and proactive in their own protection."
Related News Alerts
More by Erika Morphy
Roku Channel Store Hangs Out Shingle November 23, 2009
Roku's new channel store is based on a "one screen in the cloud" business model, said Michael Gartenberg, vice president of strategy and analysis with Interpret. "Essentially, what they are doing is taking the TV set -- whether it is a standard appliance or a high-def monster -- and enhancing it with content the consumer wants to see."
Ballmer Gives Shareholders - and Dell - Cause for Optimism November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.