You are here: silicon.com > Software > Malware

Malware

Warning: The Storm still rages on

With new avenues for attack

Tags: malware, botnet, storm

By Tom Espiner

Published: 7 May 2008 08:30 GMT

Security vendor Symantec has warned that the Storm worm, the malware which contributes to the Storm botnet, is continuing to evolve and now has two further possible avenues of attack.

A number of nascent Storm hosting domains using fast-flux techniques to mask their URLs have been identified by the security company, which issued a warning this week. Fast-flux service networks are networks of compromised computer systems with public DNS records that are constantly changing, making it more difficult to track and control criminal activities.

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

The security vendor claimed that these domains so far do not directly attempt to upload attack code. However, modifying the URL runs a script which attempts to exploit vulnerabilities in various applications, including AOL, Microsoft Internet Explorer, MySpace and RealNetworks RealPlayer.

The two possible avenues of attack are spam with links to the as-yet-unlinked-to fast-flux sites, or injecting malicious iFrame tags into legitimate websites, which would download malware onto users' machines, warned Symantec. However no such spam has been reported, the security specialist claimed.

Symantec vulnerability researcher, Vikram Thakur, said in a blog post: "What's interesting about this is that we have yet to come across any spam that may result in people visiting these domains. This is very unusual. It is also interesting to note the move from simply using social-engineering techniques to spread malware to actually exploiting vulnerabilities. In the past, the Storm worm authors would directly link to malware on websites or within spam emails. The malware wouldn't check for any particular vulnerability before planting its seed."

Thakur noted that third-party applications rather than operating-system vulnerabilities were being targeted but that "only time will allow the method employed in this wave of attacks to be confirmed".

Some security vendors have reported that the influence of Storm is waning. Storm researcher Jon Stewart, director of malware research for security vendor SecureWorks, wrote on 8 April that the Storm botnet was "only a fraction of its former self and is rapidly becoming a minor player". However, Stewart noted that the botnet was still capable of sending more than three billion spams per day.

The Storm worm botnet, a network of compromised computers, has been estimated to control between one million and five million machines, which one researcher said makes it more powerful than IBM's Blue Gene/L supercomputer. The original Storm worm code, which appeared on 19 January 2007, derived its name from the fact the first spam linking to the malware coincided with a severe winter storm in Europe.

Original article: Symantec: Evolved Storm worm attack brewing from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Web Applications Vulnerability Tester

Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...

Mid Market Account Manager-License Optimisation Sales

Selling: predominantly Microsoft and Symantec licenses, License optimisation, SAM, SLCM, Managed Services and Hosting solutions. Microsoft (UK's ...

Pre Sales Solution Architect-Data Centres or VMWare or MOSS

The objective of this role is to create an services solutions that will deliver against the customer's objectives and meet requirements for ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: