Feeds

German police arrest Sasser worm suspect

Alleged Phatbot perp also nabbed

  • alert
  • submit to reddit

Securing Web Applications Made Simple and Scalable

Updated An 18-year-old German student has admitted writing the infamous Sasser worm, following his arrest by local police on Friday.

The man (since named as Sven Jaschan) from the village of Waffensen, between Bremen and Hamburg, in the northern German state of Lower Saxony is also suspected of releasing all 28 versions of the equally notorious NetSky worm. The investigation which led to his arrest came from a tip-off to Microsoft from unspecified individuals who stand to collect a payout of up to $250,000 under the company's $5m anti-virus reward program. German papers report that Jaschan's own classmates turned him in but this remains unconfirmed.

Technical experts from Microsoft were able to verify the information received and German police, helped by investigative support from the FBI, launched an operation which led to a raid on the Jaschan's home - less than a week after Sasser began infecting hundreds of thousands of computers worldwide. Investigators seized computers and disks from his home, which he shares with his parents. His mother, Veronika, and stepfather run a small PC Help business prompting speculation their son may have written the worm in a misguided attempt to drum up business. Jaschan Junior has been released on bail after questioning by police and pending further investigations.

Confession

Frank Federau, a spokesman for German police in Lower Saxony, told Reuters: "We are absolutely certain that this really is the creator of the Internet worm because Microsoft experts were involved in the inquiry and confirmed our suspicions and because the suspect admitted to it".

Police reckon the accused created all four variants of Sasser. The alleged perp faces charges punishable by up to five years in prison if convicted in an adult court. Since he only turned 18 on April 29 he may end up getting tried in a juvenile court, where a much lighter sentence might apply.

Jaschan reportedly told police his ultimate goal with NetSky was to develop an anti-virus 'virus', which could automatically remove MyDoom and Bagle. He was encouraged by his class mates - who knew he was working on these programs - to develop the even more aggressive Sasser worm, according to German paper Süddeutsche Zeitung.

Sasser targets a recently announced vulnerability in Windows causing vulnerable machines to shutdown and reboot. The worm has caused widespread disruption affecting the operations of companies ranging from Finnish bank Sampo and Germany's Deutsche Post to the UK Coastguard. Advice on how to deal with infected or vulnerable machines can be found here.

Phatbot arrest

In a parallel move, police in the southern German state of Baden-Wuerttemberg have arrested a 21-year-old man on suspicion of creating the Agobot and Phatbot Trojans.

Investigators are refusing to speculate about links between the two virus writers or alleged connections to larger VX (virus-writing) groups, pointing out that both investigations are at an early stage. ®

Related stories

Sasser creates European pandemonium
We've seen worse than Sasser - MS
MS puts $250k bounty on virus authors' heads
Feds sexed up case Blaster suspect
FBI arrests Blaster suspect
Phatbot primed to steal your credit card details
Netsky tops virus charts by a country mile
War of the worms turns into war of words

Mobile application security vulnerability report

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.