"Storm Worm" Launched on the Internet on the tail of European Storm

author-image
afaqs! news bureau
New Update

Company News

New Delhi, January 19

A significant network attack was launched globally in the early hours of Thursday morning (GMT) using news of a European storm as the hook to lure the unsuspecting. The message, which was created and launched literally as the storm raged, is exploiting a timely widescale media event as the key mechanism for delivering its payload.

The Trojan was distributed in messages with subject line of "230 dead as storm batters Europe". The payload in this case was the Small.DAM Trojan that was downloaded into all vulnerable machines upon opening of the spam mail's attachment such as "Read More.exe". Once inside the machine, the Trojan creates a backdoor that can be exploited later by the malware authors behind the assault.

As has been seen with other attacks, the likely intention is to create a new raft of zombie computers to steal information and to further propagate large-scale spam and phishing runs.

In addition to the headline "230 dead as storm batters Europe" the spam uses a number of other provocative headlines. Attachments may be of the following filenames: "Full Clip.exe"; "Full Story.exe"; "Read More.exe" and "Video.exe".

The assault was first picked up by F-Secure Security Labs Kuala Lumpur during the very early hours of Friday European time. The timing of the assault and its detection in Asia leads researchers to believe that the assault also originated in the region.

Speaking about the case, Mikko Hypponen, Chief Research Officer at F-Secure

said: "Trojan assaults of this scale are an unfortunate and increasingly common event. What is significant here though is the timely nature of this assault in relation to the European storm. Malware gangs are clearly using every technique and even tragedies like these to gain access to vulnerable machines."

F-Secure's security products detect and block Small. DAM.

About F-Secure Corporation

F-Secure Corporation protects consumers and businesses against computer viruses and other threats from the Internet and mobile networks. We want to be the most reliable provider of security services in the market. One way to demonstrate this is the speed of our response. According to independent studies in 2004 and 2005 our response time to new threats is significantly faster than our major competitors. Our award-winning solutions are available for workstations, gateways, servers and mobile phones. They include antivirus and desktop firewall with intrusion prevention, antispam and antispyware solutions, as well as network control solutions for Internet Service Providers. Founded in 1988, F-Secure has been listed on the Helsinki Exchanges since 1999, and has been consistently growing faster than all its publicly listed competitors. F-Secure headquarters are in Helsinki, Finland, and we have regional offices around the world. F-Secure protection is also available as a service through major ISPs, such as Deutsche Telekom, France Telecom, PCCW and Charter Communications. F-Secure is the global market leader in mobile phone protection provided through mobile operators, such as T-Mobile and Swisscom and mobile handset manufacturers such as Nokia. The latest real-time virus threat scenario news are available at the F-Secure Data Security Lab weblog at http://www.f-secure.com/weblog/

For more information, please contact:

F-Secure Corporation

Patrik Runald, Senior Security Specialist

Mobile: +60 12 278 3450

Email: patrik.runald@f-secure.com

Abhishek Shrivastav

CMCG India

Tel: 29216470-3

M: 9350838866 / 9818998474

Email: abhishek.shrivastav@cmcgindia.com

shrivastavabhi10@gmail.com

Advertisment