You are here: silicon.com > Software > Malware

Malware

Expect worms in the New Year, say experts

Will you be Sober by 5 January?

Tags: sober virus, sober, virus, hate mail

By Joris Evers

Published: 8 December 2005 14:35 GMT

A new outbreak of Sober may be coming, security experts have warned, even as email systems worldwide work to get rid of the last infestation of the mass-mailing worm.

The next attack is hard-coded in the version of Sober that hit the net on 22 November, iDefense, part of VeriSign, said in a statement on Wednesday. Infected machines are set to download instructions and potentially mail out a new wave of Sober emails on 5 January, the security company said.

The attack could have a significant detrimental effect on internet traffic, as email servers are flooded.

That leaves internet users with less than a month to shore up their defences against Sober, which was the most prolific worm in 2005, security experts at iDefense said.

iDefense said: "The attack could have a significant detrimental effect on internet traffic, as email servers are flooded."

The possible outbreak could be stopped, said Mikko Hypponen, chief research officer at Finnish antivirus company F-Secure. The worm is set to download instructions from a number of sites hosted on the systems of free web space providers. These are located mostly in Austria and Germany, he said.

Hypponen added: "These free website hosters should be able to block those specific URLs this virus is trying to download from in January, so with any luck nothing will happen. There is plenty of time for the internet service providers and the antivirus people to act."

The latest Sober variant is still causing headaches for email users. Microsoft last week said the load of infected messages is causing an unspecified delay for mail sent to its Hotmail and MSN email services. Sober accounted for almost 40 per cent of all the viruses stopped by F-Secure on Wednesday, Hypponen said.

The Sober family of mass-mailing worms appears to be the work of a German speaker or group of German speakers, iDefense said. Nearly 30 variants of the worm have surfaced since October 2003, the company said.

Sober arrives as an email with a malicious attachment. The text of the email can vary and can be either in German or English. Some Sober emails have included Nazi propaganda, while others posed as messages from the CIA, the FBI and the UK's National High-Tech Crime Unit.

iDefense believes a 5 January attack may be spreading more Nazi propaganda. The date coincides with the 87th anniversary of the founding of the Nazi party.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Head of Sales and Customer Relations

Develop major areas of focus and key selling messages/training for each Operational Group (OG)/industry vertical, working closely with OG leads and ...

E- Learning Manager

You will negotiate with internal clients and subject matter experts for publication and delivery timeframes, manage the workload and development of ...

German Speaking Accounts Payable Clerk London TEMP

Global Client based in London City is looking for a German speaking Purchase Ledger Clerk with strong SAP and German. Please send through your CV for ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: