Mytob Mania Won't Stop
2005-06-17 16:39:00
The Mytob worm family keeps popping out newborns, security firms noted Friday, with no signs that the variants will stop any time soon.
The Mytob worm, which first appeared in late February, is a mass-mailed worm that hijacks addresses from compromised PCs to spread using its own SMTP engine, drops a backdoor Trojan so more malicious code can be added to the infected system, tries to shut down security software already on the computer, and blocks access to a large number of security and update-oriented Web sites.
Security firms such as Symantec have tracked and labeled over 130 different variations on the Mytob worm in the last three-and-a-half months. So many variants have appeared, using so many different techniques -- including phishing-style tactics -- that some analysts believe the group responsible is crafting a "super" worm.
In the last 7 days, Symantec's identified 19 different Mytobs, an average of 2.7 new variants per day, an unheard-of number.
"In the last 24 hours, the Mytob family has accounted for 58 percent of all [virus] reports," the U.K.-based to Sophos said in a statement. Fourteen of the top 20 threats, Sophos added, were Mytob variants.
"There is nothing to suggest that the slew of Mytobs is tailing off," said Carole Theriault, a senior security consultant at Sophos.
Although most Mytob variants propagate via e-mail, some -- including several launched in June -- scan the Net for PCs vulnerable to a variety of Windows vulnerabilities, such as the LSASS bug that Microsoft patched more than a year ago.
One such vulnerability-sniffing Mytobs -- dubbed Mytop.ea by Symantec -- now accounts for fully 15 percent of all malicious code processed by Sophos, said Theriault.
"Patching against operating system vulnerabilities has never been more important. Users want to ensure that their barriers are up and ready to thwart these beasties," she added.
|
|
Microsoft Lays Down Law On German Spammer Microsoft's German unit on Monday announced that it had sued an unnamed company in the state of North Rhine-Westphalia for spamming the U.S.-based company's Hotmail service. Microsoft To Build Web-Based 'Communicator' Microsoft is working on a Web client for its real-time chat capabilities. Salesforce.com Launches Upgrades, 'Operating System' For On-Demand CRM Salesforce.com on Tuesday released major upgrades of its online customer-relationship management software, and launched a new single-platform for customers to manage and access all of the company's hosted applications.
MSN Tests New Local Search Services
Microsoft Corp. is testing a local-search service on its MSN portal that includes directory information on businesses and residences, corresponding maps and aerial images. EBay Launches Site For Open-Source Developers EBay Inc. on Tuesday launched an online forum for open-source developers interested in accessing source code for various tools and sample applications for adding EBay services to web applications. Online Travel Shoppers Split Between Airlines, Agency Websites While more than half of online travel shoppers begin their search with a travel agency, they're evenly split between those sites and ones from airlines when it comes time to book flights, a research firm said Tuesday. Orlando Drops City-Run Wi-Fi The city of Orlando, Florida has shut down the free Wi-Fi service it launched in its downtown area, the Orlando Sentinel reported Tuesday. Online Media, Entertainment Thriving Despite Piracy Under pressure from piracy and the illegal copying of content, the online media and entertainment industries are being reinvigorated by new drivers including the online distribution of music, films, books, and video games, according to a report released Wednesday. MCI Releases VPN For DSL Access to Networks MCI Inc. has announced two new additions to its Secure Interworking Gateway (SIG) Services suite designed to help enterprises secure access to their networks. Banks Scramble To Contain Damage From CardSystems Hacking Incident Banks that issue credit and debit cards are moving rapidly to contain the damage caused by the potentially massive theft of card information from a transaction-processing company that was disclosed last week.
|