Feeds

German police arrest Sasser worm suspect

Alleged Phatbot perp also nabbed

  • alert
  • submit to reddit

The Essential Guide to IT Transformation

Updated An 18-year-old German student has admitted writing the infamous Sasser worm, following his arrest by local police on Friday.

The man (since named as Sven Jaschan) from the village of Waffensen, between Bremen and Hamburg, in the northern German state of Lower Saxony is also suspected of releasing all 28 versions of the equally notorious NetSky worm. The investigation which led to his arrest came from a tip-off to Microsoft from unspecified individuals who stand to collect a payout of up to $250,000 under the company's $5m anti-virus reward program. German papers report that Jaschan's own classmates turned him in but this remains unconfirmed.

Technical experts from Microsoft were able to verify the information received and German police, helped by investigative support from the FBI, launched an operation which led to a raid on the Jaschan's home - less than a week after Sasser began infecting hundreds of thousands of computers worldwide. Investigators seized computers and disks from his home, which he shares with his parents. His mother, Veronika, and stepfather run a small PC Help business prompting speculation their son may have written the worm in a misguided attempt to drum up business. Jaschan Junior has been released on bail after questioning by police and pending further investigations.

Confession

Frank Federau, a spokesman for German police in Lower Saxony, told Reuters: "We are absolutely certain that this really is the creator of the Internet worm because Microsoft experts were involved in the inquiry and confirmed our suspicions and because the suspect admitted to it".

Police reckon the accused created all four variants of Sasser. The alleged perp faces charges punishable by up to five years in prison if convicted in an adult court. Since he only turned 18 on April 29 he may end up getting tried in a juvenile court, where a much lighter sentence might apply.

Jaschan reportedly told police his ultimate goal with NetSky was to develop an anti-virus 'virus', which could automatically remove MyDoom and Bagle. He was encouraged by his class mates - who knew he was working on these programs - to develop the even more aggressive Sasser worm, according to German paper Süddeutsche Zeitung.

Sasser targets a recently announced vulnerability in Windows causing vulnerable machines to shutdown and reboot. The worm has caused widespread disruption affecting the operations of companies ranging from Finnish bank Sampo and Germany's Deutsche Post to the UK Coastguard. Advice on how to deal with infected or vulnerable machines can be found here.

Phatbot arrest

In a parallel move, police in the southern German state of Baden-Wuerttemberg have arrested a 21-year-old man on suspicion of creating the Agobot and Phatbot Trojans.

Investigators are refusing to speculate about links between the two virus writers or alleged connections to larger VX (virus-writing) groups, pointing out that both investigations are at an early stage. ®

Related stories

Sasser creates European pandemonium
We've seen worse than Sasser - MS
MS puts $250k bounty on virus authors' heads
Feds sexed up case Blaster suspect
FBI arrests Blaster suspect
Phatbot primed to steal your credit card details
Netsky tops virus charts by a country mile
War of the worms turns into war of words

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.