Feeds

Hackers plot to create massive botnet

It's raining malware

  • alert
  • submit to reddit

Protecting against web application threats using SSL

Computer Associates has warned of a co-ordinated malware attack (CMA) described as among the most sophisticated yet unleashed on the net. The attack involves three different Trojans – Glieder, Fantibag and Mitglieder – in a co-ordinated assault designed to establish a huge botnet under the control of hackers. CA reckons that access to the compromised PCs is for sale on a black market, at prices as low as five cents per PC.

CA security researchers reckon the three items of malware have been combined to maximise the potency of the overall assault. The elements of the attack include:

  • Glieder-AK: the "infantry element" of the malware attack infects systems, open up backdoors that exploited by the follow-on Trojans. On 1 June, 2005, eight new Glieder variants appeared in rapid succession and quickly spread. "The apparent objective is to get to as many victims as fast as possible with a lightweight piece of malware," CA said.
  • The Fantibag Trojan further disables the security features of compromised systems. It exploits networking features of target systems to prevent those systems from being able to communicate with anti-virus firms or with Microsoft’s Windows update site, so isolating infected systems.
  • The Mitglieder Trojan opens a backdoor on a compromised system, leaving them under the control of hackers.

"The co-ordination between the Glieders and Fantibag Trojans can have a potentially devastating effect on desktop systems. This phenomenon is indicative of how malware is becoming increasingly sophisticated and more directly linked to criminal endeavours," said Simon Perry, CA's VP of security strategy, EMEA.

MyTob 'dumbs down' virus creation

Confusingly, the Glieders and Fantibag Trojans are both known as Bagle downloader variants by other anti-virus vendors. Altogether it’s been an exceptionally busy week for new computer viruses. As well as the attack described by CA numerous new versions of the MyTob worm have also been produced. These variants typically pose as warnings from sys admins about the misuse of a potential victim's email account with Subject lines such as "*DETECTED* Online User Violation, Your Email Account is Suspended For Security Reasons and Account Alert."

When an infected attachment is launched, MyTob-CM (the most common of this week's variants) attempts to turn off security applications. It also attempts to open a backdoor on infected Windows PC, allowing hackers to exploit compromised systems. Anti-virus firm Sophos reckons the creators of MyTob appear to be a group of virus writers called Hellbot. Carole Theriault, security consultant at Sophos, said similarities in code point to possible links between the authors of MyTob and the long running MyDoom series of worms.

What makes MyTob stand out as a trend is less the number of recorded infections, which are relatively low, than how rapidly it is propagating, according to Trend Micro. The Japanese ant-virus firm has identified 125 new variants spotted in less than three months. "MyTob appears to have been made even easier to implement and vary. This has been a honey pot for lesser skilled programmers - script kiddies - to make their own variants, contributing to the rapid growth rate of MyTob variants in the wild," it said.

One variant, MyTob-AR, seen earlier this week added spyware and adware to infected computers. This malware can be used to track usage including keystrokes and could be used to steal valuable personal information such as passwords, a worrying development in the evolution of the malware family.

It almost goes without saying but all the MyTob variants, along with the Bagle downloaders, infects only Windows PCs. Apple, Linux and those few souls out there still running OS/2 are all immune, as usual. Standard defence precautions against viral attacks apply in defending against the various new Windows worms and Trojans released this week. Windows users need to apply the latest security patches, update anti-virus tools and to resist the temptation to open suspicious-looking emails. Applying a personal firewall wouldn't go amiss either. ®

related stories

Blank virus blanks email
Window of exposure lets viruses run rampant
Trojan attack takes files hostage
Sober worm tops May viral charts

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.