29 Apr 2010
Security researchers have spotted new variants of the Storm malware within the past few days, suggesting that the botnet's handlers are looking to piece together a new network of infected systems.
Storm first appeared in January 2007, taking its name from the videos of flooding in Europe that were used to lure users into downloading the Trojan installer.
The botnet reigned for nearly two years, and was constantly being re-invented to lure new users with videos based on holidays and current events.
Storm was believed to have been all but eliminated by early 2009, pushed out by newer botnets and increased security efforts. But the new incarnation of the malware carries some key differences to the old infection.
McAfee Labs researcher Toralv Dirro cited work from a group of German researchers which found that the malware had dropped its peer-to-peer communication systems and is using a standard HTTP connection.
"This change basically means that the new botnet is 'just' another botnet among the many thousands active today, with nothing special except the relationship with its notorious predecessor," he wrote in a blog post.
"However, the group running Storm has proven to be very resourceful in the past."
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Implementation Consultant - Business Intelligence Software...
SQL Server DBA, ETL, SSIS, Datawarehousing, Financial...
Job description *Customer facing: should be able to...
PHP / MySQL / Zend Framework Developer - Chelmsford...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?