Original URL: http://www.theregister.co.uk/2007/08/29/storm_hits_blogger/
Miscreants behind the Storm Worm have begun attacking Blogger, littering hundreds of pages with titillating messages designed to trick visitors into clicking on poisonous links.
By now, anyone who doesn't live under a rock is familiar with the spam messages bearing subjects such as "Dude what if your wife finds this" and "Sheesh man what are you thinkin" and including a link to a supposed YouTube video. Recipients foolish enough to click on the link are taken to an infected computer that tries to make their machine part of a botnet.
Now Storm Worm, the malware responsible for those messages, has overrun Google-owned Blogger. According to one search (http://www.google.com/search?as_q=+%22dude+what+if+your+wife+finds+this%22+OR+%22sheesh+man+what+are+you+thinkin%22++OR+%22man+your+insane%22&hl=en&num=100&btnG=Google+Search&as_epq=+&as_oq=&as_eq=&lr=&as_ft=i&as_filetype=&as_qdr=all&as_nlo=&as_nhi=&as_occt=any&as_dt=i&as_sitesearch=blogspot.com&as_rights=&safe=off), some 424 Blogger sites have been infected. The actual number is probably higher because our search contained only a small fraction of the teasers used by Storm.
"What it really shows to me is how pernicious these guys are and they're indefatigable in trying to get into every place," said Alex Eckelberry, president of Sunbelt Software who blogged about the Blogger assault earlier (http://sunbeltblog.blogspot.com/2007/08/storm-worm-hits-blogger.html). "This is a voracious, voracious worm. I don't think anybody in malware research has seen anything like Storm."
Storm has already gone through more lives than a pack of feral cats. It started out in January as an email promising information about a winter storm that was sacking Northern Europe. Since then it's offered sexy photos, electronic greeting cards and login credentials for various online memberships. According to researchers, Storm has infected more than 1.7 million hosts.
Storm's ability to crack Google's defenses is yet another testament to the resiliency of the malware. Google tends to outshine competitors in blocking spam and sniffing out sites that serve up Trojans.
It's unclear exactly how Storm was able to penetrate Blogger. We're guessing it's through a feature that allows bloggers to submit posts through pre-established email addresses, saving them the hassle of having to access Blogger's control panel. Alas, it may also be enabling Storm to yet again morph.
Representatives from Google didn't respond to emails asking for comment. ®
Move over Storm - there's a bigger, stealthier botnet in town (7 April 2008)
http://www.theregister.co.uk/2008/04/07/kraken_botnet_menace/
Russian FSB 'protecting' Storm Worm gang (31 January 2008)
http://www.theregister.co.uk/2008/01/31/storm_worm_protection/
Miscreants subvert search results to punt malware (28 November 2007)
http://www.theregister.co.uk/2007/11/28/botnets_use_search_to_build_zombies/
The balkanization of Storm Worm botnets (15 October 2007)
http://www.theregister.co.uk/2007/10/15/storm_trojan_balkanization/
Brute force attack yields keys to Google's kingdom (1 October 2007)
http://www.theregister.co.uk/2007/10/01/google_spam_infiltration/
Google malware watchdogs bite mom-and-pop shops (21 September 2007)
http://www.theregister.co.uk/2007/09/21/google_malware_warning/
Storm Worm linked to spam surge (14 September 2007)
http://www.theregister.co.uk/2007/09/14/storm_worm_analysis/
VXers rain on YouTube's parade (29 August 2007)
http://www.theregister.co.uk/2007/08/29/storm_worm_latest/
Storm Worm of a thousand faces (21 August 2007)
http://www.theregister.co.uk/2007/08/21/mutating_storm_worm/
Storm worm authors switch tactics (20 August 2007)
http://www.theregister.co.uk/2007/08/20/storm_vxers_refine_tactics/
Fake e-cards signal massive DDoS attack (7 August 2007)
http://www.theregister.co.uk/2007/08/07/storm_worm_spike/
Security consultant's blog found pushing crudware (4 July 2007)
http://www.theregister.co.uk/2007/07/04/security_blog_pushes_crudware/
Rival malware gangs wage turf war (1 July 2007)
http://www.theregister.co.uk/2007/07/01/malware_gang_war/
Blogger.com 'riddled' with malware (15 March 2007)
http://www.theregister.co.uk/2007/03/15/blogger_malware/
Stormy weather for malware defenses (7 March 2007)
http://www.theregister.co.uk/2007/03/07/storm_malware_defenses/
Imperfect Storm aids spammers (19 February 2007)
http://www.theregister.co.uk/2007/02/19/storm_worm_stockpatrol/
Anatomy sheds new light on Storm Worm (9 February 2007)
http://www.theregister.co.uk/2007/02/09/storm_worm_anatomy/
© Copyright 2008