Feeds

Outbreak of viruses disguised as vaccines

Dangerous V3 update

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Computer virus writers are disguising viruses as anti-virus updates in an attempt to trick users into running malicious code.

Korean security firm, Dr. Ahn's Laboratories, has warned its users about a malicious program that arrives by email disguised an update to its anti-virus software, V3. In reality the message contains an attachment, "V3update.com", which, if opened , can wipe a victim's hard drive.

The infected message appears to be sent from Ilchi.net, though the firm says it never dispatched such an email.

According to reports in the Korean Herald, a national police cyber investigation team is currently investigating the cases.

Dr. Ahn's said there have been cases where malicious software was posted to data exchange platform disguised as V3. However, this is the first time a users have received such a program by email.

The technique of disguising malicious code as security software was also used against an American software security firm, Central Command, last week.

Following the discovery of the spread of an internet worm, called I-Worm.XTC, which masquerades as a virus protection update, Central Command was forced to issue a security advisor to its customers and partners.

The worm, which infects Windows 95/98/Me/NT/2000 computers, has a spoofed email address so that to a casual observer it appears to come from Central Command. It uses the temporary internet files folder to search through cached pages for e-mail addresses, unlike most such viruses which use the Outlook address book. I-Worm.XTC can also be remotely controlled through Internet Relay Chat.

Graham Cluley, senior technology consultant at Sophos, said that both the Korean case and what happened with Command Software showed that, whilst it is not a new technique, virus writers are disguising their work as security software to get users to run it and in an "attempt to discredit antivirus companies".

Cluley added that downloading antivirus software from websites or using CDs for updates is more secure and should be preferred to obtaining software updates by email. ®

Related Stories

Virus prevents you asking for help
Viruses prey on porn lovers

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Sway: Microsoft's new Office app doesn't have an Undo function
Content aggregation, meet the workplace ... oh
Do Moan! MONSTER 6-day EMAIL OUTAGE hits Domain Monster
Customers freaked out by frightful service
Sign off my IT project or I’ll PHONE your MUM
Honestly, it’s a piece of piss
Return of the Jedi – Apache reclaims web server crown
.london, .hamburg and .公司 - that's .com in Chinese - storm the web server charts
NetWare sales revive in China thanks to that man Snowden
If it ain't Microsoft, it's in fashion behind the Great Firewall
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.