By Fred J. Aun TechNewsWorld Part of the ECT News Network
01/19/07 11:01 AM PT
A massive malware attack spread throughout the world Thursday and Friday by teasing e-mail recipients to open infected messages supposedly about European wind storms. The attackers use of the subject line "230 dead as storm batters Europe" was an effective way to lure careless computer users into opening mail infected with the "Storm Worm" virus.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
"Storm Worm" is the name that seems to have stuck for a massive malware attack that spread Thursday and Friday by teasing e-mail recipients to open infected messages supposedly about European wind storms.
The attackers use of the subject line "230 dead as storm batters Europe" was an effective way to lure careless computer users into opening mail infected with the Small.DAM Trojan. Fierce winds were battering Europe simultaneously with the release of the messages.
The Trojan was launched when users clicked on attachments to the messages that said "Full Clip.exe," "Full Story.exe," "Read More.exe" and "Video.exe."
Different Variations
However, the perpetrators also sent similarly infected, but differently titled, messages to thousands of other inboxes. These messages titillated readers into clicking the attachments by suggesting they would see videos of U.S. Secretary of State Condoleeza Rice kicking German Chancellor Angela Merkel which, unlike the storm, did not actually happen.
Others offered information or video pertaining to "British Muslims Genocide," "Naked teens attack home director" and "A killer at 11, he's free at 21 and kill again!"
The interesting part of the attack was the creativity and timing, according to Graham Cluley, senior technology consultant for Sophos. "Everyone is concentrating on the storm angle of it, which is only one headline of course," he said. "That was topical in Europe, where we've had some very, very bad weather. But another worthwhile thing to consider is the way they were trying to use humor to get people to open the mail as well."
Many people enjoy reading jokes or weird news tidbits sent by e-mail, Cluley noted. "People who receive that and think they got a video attached to the e-mail might think, 'That sounds funny. I might just click on it to have a look.' This is taking advantage of the way people share jokes and videos. It's not just the news aspect of it. There is all sorts of social engineering going on here."
Topical Messages Enhance Effectiveness
The attack shows that hackers are staying abreast of world news. The European storm message was "created and launched literally as the storm raged," according to Helsinki, Finland-based security company F-Secure.
The attack was powerful and widespread but, apparently, short-lived, F-Secure's Chief Research Officer Mikko Hypponen told TechNewsWorld.
"This is over," he added. "They stopped the attack. Whoever sent this isn't doing it anymore. Looking at the rate of e-mails being sent, we believe they were targeting European users and it was a nine-hour window starting [Thursday] night and finishing at about 10 a.m. [Friday morning]."
The storm-related message was apparently meant to be awaiting users in the morning, according to Hypponen.
"The people woke up and saw news about a massive storm," he explained. "They went to work and found an e-mail about the storm in their inboxes. Of course it's going to work much better than the usual attack. They gained access to probably tens of thousands of computers in Europe."
Zombie Network
The hackers, before the Thursday-through-Friday attack, had already gained control of thousands of PCs by prior malware infection, Hypponen noted. "They instructed those computers to do this 10-hour spam run. They had a very large [zombie] network. Now it's much larger."
The "huge attack" might have worked too well, in a sense, suggested Sophos' Cluley. "The fact that this is making headlines actually works against the hackers" because so many people and antivirus companies are now aware of the incident, thanks to its creative and "colorful" nature.
Encrypted Virus Code: New Spin on Old Trick? January 18, 2007
Viruses using encrypted code are nothing new for hackers or security developers. New advisories, however, are surfacing that warn of new viruses that use modified executable codes. Security firms disagree on the actual size of the threat, but if it materializes, it could force antivirus software makers to redesign their detection engines, possibly making them slower and more difficult to use.
Related Stories
Google Apologizes for Virus Distribution November 10, 2006
Google acknowledged that it inadvertently e-mailed postings to some 50,000 users that contained the Kama Sutra virus. The search giant revealed the mix-up in a posting to its Video Blog site. "We're sorry for any inconvenience, and we're taking steps to ensure that this doesn't happen again," the message said.
E-Mail Reputation: An Important Factor in Restoring Trust September 19, 2006
In spite of taking multiple steps to ensure the trustworthiness of e-mail communication, "in the world of e-mail, mistakes can happen," said Sal Tripi, director of operations at Publishers Clearing House. "You can be added to a blacklist [or] your content can trigger a spam filter, so checking every morning is a valuable service."
Can Authentication Restore Trust in E-Mail? August 16, 2006
Fortunately, authenticated e-mail helps both senders and recipients. To the sender, the most important benefit is the improved deliverability of e-mail. The average consumer benefits when authentication is used by mailbox providers in conjunction with spam-fighting processes.
Related News Alerts
More by Fred J. Aun
Intel Feels Fury of OLPC Scorned January 09, 2008
"Over the entire six months it was a member of the association, Intel contributed nothing of value to OLPC," said OLPC. "Intel never contributed in any way to our engineering efforts and failed to provide even a single line of code to the XO software efforts even though Intel marketed its products as being able to run the XO software."
Yahoo Pumps Up Mobile Effort in Bid to Get a Jump on Google January 08, 2008
"Yahoo's ultimate goal is to bring the best possible Internet experience to the billions of mobile consumers around the globe," said Marco Boerries, executive vice president of Yahoo's Connected Life division. "We believe that to succeed on such a scale, the best strategy is to open up our mobile platform in order to tap the innovation and talent of the world's developers and publishers."
Wikia's Search Philosophy: It Takes a Village to Challenge a Giant January 07, 2008
"What you see here is our first alpha release," says a greeting on the Wikia Search site. "We are aware that the quality of the search results is low. Of course, before we start, we have no user feedback data. So the results are pretty bad. But we expect them to improve rapidly in coming weeks, so please bookmark the site and return often."