The Register® — Biting the hand that feeds IT

Feeds

Fake e-cards signal massive DDoS attack

Storm worm's a brewin'

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Security researchers are reporting a sharp increase in the number of machines infected by the Storm Worm, prompting speculation that its authors, who so far have limited their activities to spam, intend to use it for more destructive purposes, such as launching massive denial of service attacks.

In June and July, internet security provider SecureWorks counted 1.7m unique hosts carrying the Storm Worm, compared with just 2,817 from January to May, according to Joe Stewart, a senior researcher with the company. The number of attacks blocked by SecureWorks has similarly skyrocketed, from 71,342 for the first five months of the year to 20.2m since June.

Just about anyone with an email account is painfully familiar with Storm, whose most recent spam messages bear subjects such as "You've received a greeting e-card from a worshipper." Once recipients follow the link and install the malicious code, they become part of the same network as the original sender and either churn out the same e-card messages or spam containing PDF files that tout penny stocks.

The spike in the number of infected machines is leading to speculation that the people maintaining the Storm network are aspiring to greater things.

"In most cases, a botnet of 1,000 or 10,000 is plenty to do what these guys want to do, which is spam or DDoS somebody," Stewart told El Reg. "We're wondering if perhaps the idea of having a virtually unstoppable DDoS net might be driving this."

One possible plan may be to build a network that could be leased out to hackers so they can launch a massive attack on a large company or entire country. Stewart, who frequently monitors underground forums where cyber criminals advertise their products and services, says little is known about the people connected with Storm. He has yet to see individuals identify themselves as being affiliated with the network.

The Storm Worm got its name after malware-laced mass emails that first spread in January promised information about winter storms that ravaged Northern Europe. Since then, the email topics have changed many times, demonstrating a strong ability in its authors to trick recipients into clicking through so they become infected.

Storm Worm combines this social-engineering savvy with a technical prowess that relies on peer-to-peer technology for updates rather than a centralized command and control channel on an internet relay chat network. And therein lies the secret to Storm's resiliency.

"Instead of being connected to a single IRC server, it's connected by p2p, so there's no head to cut off," said Allysa Myers, a virus research engineer at McAfee. "It's been difficult to do anything on a larger level to try to kill this thing off."

Storm infections can also be extremely hard to detect and remove because they frequently alter executables that get loaded during startup, rather than relying on traditional, and better understood, techniques of modifying the startup registry. For example, recent variants of the Storm Worm, which also goes by the name of W32/Newar, "parasitically infect" tcpip.sys files.

"It's something that has been used by a number of different families over the last six months or so, and Newar [authors] have seen this tactic used by other virus writers and have started to incorporate it," Myers said. ®

Agentless Backup is Not a Myth

Latest Comments
Anonymous Coward

Linux Virus?

Come on, all you Linux boys! As 4.1.3_U1 pointed out, you don't need root access to send spam on a Linux box. Yes, Windows IS less secure than Linux, but most people don't want to have to recompile the core just to add a new USB memory stick!

To think that these ******* that write these viruses WON'T get around to Linux is just stupid. Especially now that 2 different manufacturers are shipping Linux and instead of the OS being the reserve of competent IT users, Joe Bloggs is going to be using it. How many new users are going to make mistakes and leave the root liable to attack?

We all know that Windows is the main target because it's the biggest (and easiest).

0
0

@Morely Dotes

I think you'll find that a lot of the tasks which malware writers want to achieve do not require root access: fire off a spam email; ddos; p2p or im client for command and control.

Many distros even enable cron for normal users by default.

Maybe the whole machine wouldn't be owned, but does that matter if it performed its tasks?

@anon "Linux is as vulnerable as XP ... NOT!" said "stealthy 100MB viruses"

What about a small statically linked executable that searched for likely mail clients which might happen to be installed (starting with 'sendmail' perhaps?).

The hardest part would probably be writing something that the (idiot) user could just install with a few clicks (or a zero day browser exploit). Maybe that even "couldn't be done". Maybe nobody's bothered trying.

0
0
Anonymous Coward

What to do with many many MANY MANY bots...

Maybe they just want to massively DDOS google?

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Internet fraud still stings suckers
Australians twice as gullible as Americans