Feeds

Sober infected PCs spew right-wing 'hate spam'

Neo-botnet

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Virus writers turned PCs infected with the Sober-P worm into relay stations for right-wing propaganda using backdoor access into compromised machines to load malicious code.

Sober-Q was downloaded from Saturday (14 May) onwards onto computers infected by recent Sober-P worm. The mass mailing Sober-P worm tricked recipients into thinking they had won tickets to the 2006 World Cup football tournament, duping numerous victims since its first appearance on 2 May.

Sober-Q doesn't spread itself via e-mails (even though it's been lumped with the Sober worm family it lacks any self-replicating function, so it's not a virus). The malware is essentially a spam engine - bulk mailing links to websites with right-wing German nationalistic content to domains with suffixes '.de', '.ch', '.at' or '.li'. Sober-Q also spams messages in English to domains outside the German-speaking world.

Examples of Sober-Q subject lines include: "Multi-Kulturell = Multi-Kriminell" (Multi-culturally = multi-criminally); "Dresden 1945" and "The Whore Lived Like a German".

"Spam has been traditionally regarded as annoying messages that promote Viagra, porn and low cost mortgages," said Scott Chasin, CTO of email security firm MX Logic. "But for the past year we have seen a trend in which worm authors are using spam not to hawk goods, but as a tool for political propaganda."

In June 2004, a spambot network used PCs infected by another variant of the Sober worm to disseminate political spam in one of the first attacks of its kind. The spread of the hate mail spam messages generated by Sober-Q coincides with ongoing celebrations throughout Europe this week marking the 60th anniversary of the end of World War II in Europe. ®

Related stories

Sober worm shakes Windows security
Sober worm speaks with forked tongue
Sober email worm gives Windows users the DTs
FBI issues Sober notice over Windows worm
World Cup worm gives Windows users the willies

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.