Feeds

Traumatised email servers mark Love Bug anniversary

Six years ago today

The Power of One eBook: Top reasons to choose HP BladeSystem

Thursday 4 May marks the sixth anniversary of the spread of the infamous Love Bug (AKA ILOVEYOU) worm, a mass mailer that infected numerous Windows computers worldwide. Even those not infected directly found their email inboxes filed with junk, an experience that was to be repeated several times over subsequent years.

The Love Bug worm tricked users into thinking they'd received a message from a secret admirer. But if the attachment was opened on a Windows PC, the worm would leave it infected while forwarding copies of itself to email addresses harvested from compromised PCs. The suspected author of the worm, Filipino student Onel de Guzman, was arrested but escaped prosecution because of a lack of relevant laws. Laws designed to combat computer misuse in the Philippines were only introduced in June 2000 and weren't backdated, allowing de Guzman to avoid trial.

The worm used VBScripts to spread, popularising a technique that was then comparatively rare. Security experts attributed its success in spreading to its use of a love bait as an enticement, which proved to be a powerful psychological draw to bored office workers and consumers. The worm was first spotted on 3 May 2000, but its spread didn't begin in earnest until the following day, 4 May 2000.

Much has changed in the malware landscape over the intervening six years, according to UK-based net security firm Sophos. The Love Bug, and the less prolific but still virulent Melissa worm that preceded it, heralded the hay-day of mass-mailing worms that relied on social engineering to spread such attacks are now rare. Targeted Trojan and spyware attacks now represent a far greater security challenge.

In 2001, 21 per cent of all threats discovered by Sophos were Trojan horses. By April 2006 this figure had shot up to 86 per cent as hackers used Trojan horses to download malicious code, spy on users, steal information, or seize control of infected PCs. The Love Bug was conceived as a means of stealing internet connection passwords in order to give its creators cheap access to the net, making it something of a forerunner to today's menaces.

The Love Bug popularised the use of social engineering tricks to spread email worms by tricking users into double-clicking on malicious attachments. For example, the Anna Kournikova worm posed as pictures of the Russian tennis pin-up. Other malware strains offered infected files supposedly connected to Britney Spears, Paris Hilton and Jennifer Lopez.

Sophos experts say financially-motivated hackers now prefer to use Trojan horses rather than mass-mailing worms because there's a greater pay off in avoiding the public attention a major outbreak brings. Publicity about a viral epidemic tends to make users more wary, while creating a motive for police to apply more resources towards identifying culprits, an outcome cyberciminals are keen to avoid. ®

Designing a Defense for Mobile Applications

More from The Register

next story
DARPA-derived secure microkernel goes open source tomorrow
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.