Feeds

Outbreak of viruses disguised as vaccines

Dangerous V3 update

  • alert
  • submit to reddit

Boost IT visibility and business value

Computer virus writers are disguising viruses as anti-virus updates in an attempt to trick users into running malicious code.

Korean security firm, Dr. Ahn's Laboratories, has warned its users about a malicious program that arrives by email disguised an update to its anti-virus software, V3. In reality the message contains an attachment, "V3update.com", which, if opened , can wipe a victim's hard drive.

The infected message appears to be sent from Ilchi.net, though the firm says it never dispatched such an email.

According to reports in the Korean Herald, a national police cyber investigation team is currently investigating the cases.

Dr. Ahn's said there have been cases where malicious software was posted to data exchange platform disguised as V3. However, this is the first time a users have received such a program by email.

The technique of disguising malicious code as security software was also used against an American software security firm, Central Command, last week.

Following the discovery of the spread of an internet worm, called I-Worm.XTC, which masquerades as a virus protection update, Central Command was forced to issue a security advisor to its customers and partners.

The worm, which infects Windows 95/98/Me/NT/2000 computers, has a spoofed email address so that to a casual observer it appears to come from Central Command. It uses the temporary internet files folder to search through cached pages for e-mail addresses, unlike most such viruses which use the Outlook address book. I-Worm.XTC can also be remotely controlled through Internet Relay Chat.

Graham Cluley, senior technology consultant at Sophos, said that both the Korean case and what happened with Command Software showed that, whilst it is not a new technique, virus writers are disguising their work as security software to get users to run it and in an "attempt to discredit antivirus companies".

Cluley added that downloading antivirus software from websites or using CDs for updates is more secure and should be preferred to obtaining software updates by email. ®

Related Stories

Virus prevents you asking for help
Viruses prey on porn lovers

Application security programs and practises

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Do YOU work at Microsoft? Um. Are you SURE about that?
Nokia and marketing types first to get the bullet, says report
Microsoft takes on Chromebook with low-cost Windows laptops
Redmond's chief salesman: We're taking 'hard' decisions
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
EU dons gloves, pokes Google's deals with Android mobe makers
El Reg cops a squint at investigatory letters
Chrome browser has been DRAINING PC batteries for YEARS
Google is only now fixing ancient, energy-sapping bug
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.