Feeds

$250K reward for Sasser virus informants

That's what friends are for

  • alert
  • submit to reddit

Internet Security Threat Report 2014

The two people who helped identify the creator of the infamous Sasser worm in 2004 will share a reward of $250,000, Microsoft confirmed Friday. News of the payment under the software giant's Anti Virus Reward Program comes after a German court sentenced Sven Jaschan, 19, self-confessed author of Sasser to 21 months probation and a community service order following his conviction on computer sabotage offences.

Sasser is a network aware worm that exploited a well-known Microsoft vulnerability (in Windows Local Security Authority Subsystem Service - MS04-011) to infect thousands of systems in May 2004. The worm has caused widespread disruption affecting the operations of companies ranging from Finnish bank Sampo and Germany's Deutsche Post to the UK Coastguard.

Jaschan was arrested in the village of Waffensen near Rotenburg, in northern Germany, on suspicion of writing and distributing the Sasser worm within days of the beginning of the Sasser pandemic. The teenager later confessed to police that he was both the author of Sasser and the original creator of the NetSky worm.

Jaschan was arrested after a tip-off to Microsoft from individuals (believed to be Jaschan's erstwhile friends but Microsoft is keeping their names secret) who took advantage of Microsoft's Anti-Virus Reward Program. Investigators questioned Jaschan's mates on suspicion of assisting his virus writing activities but none were charged. In a statement, Microsoft said it was a condition of its anti-virus tip-off reward that recipients had no criminal involvement in a case.

Microsoft earmarked $5m in establishing its the Anti-Virus Reward Program back in November 2003. The scheme is designed to "help law enforcement agencies identify and bring to justice those who illegally release damaging worms, viruses and other types of malicious code on the Internet". Microsoft is putting up the money but it is up to investigators to decide if anyone qualifies for the bounties, payable on arrest and conviction of a virus writer. The Saser reward represents the first payment under the scheme, a Microsoft spokeswoman confirmed. ®

Related stories

Sasser worm creates havoc
Sasser creates European pandemonium
German police arrest Sasser worm suspect
Police probe Sasser informant
German police raid five homes in Sasser case
Sasser kid blamed for viral plague
Sasser author gets IT security job
Sasser author admits guilt
Sasser suspect walks free
MS puts $250k bounty on virus authors' heads
AV vendors shun MS bounty hunters

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.