All the latest UK technology news, reviews and analysis

Dorf storms the malware charts

by Robert Jaques

31 Jan 2007

Be the first to comment

  • Tweet this

The recently discovered Dorf malware has already had a "massive impact" on computer users worldwide, security experts warned today.

The latest malware monitoring data from Sophos said that Dorf has rampaged to the top of the monthly malware threat chart to account for almost 50 per cent of all malware seen during January.

Dorf was aggressively spammed out posing as breaking news of deaths caused by stormy European weather during January.

Later in the month the authors changed tack and launched a second campaign disguising the malware as a romantic email greeting card.

Elsewhere in the Sophos top 10, Netsky, Mytob and Stratio remain rooted in second, third and fourth places respectively, accounting collectively for one third of all malware reports.

"Spammed out with hard-hitting headlines and the promise of exclusive news content, the Dorf malware, or Storm Trojan, moved at gale force speeds and battered inboxes worldwide in an attempt to compromise users' PCs," said Carole Theriault, senior security consultant at Sophos.

"It was not a particularly sophisticated form of attack, as preying on public interest by using breaking news events is a tried and trusted trick and has proven to be a remarkably effective method of fooling recipients into lowering their guard."

Sophos has seen more than 2,500 variants of the Dorf malware, almost a third of the new threats identified during January 2007.

The majority were intercepted by Sophos' proactive Behavioral Genotype Protection technology even before they were formally identified as belonging to the Dorf family of malware.

According to the firm, the proportion of infected email, while substantially higher than in December 2006, is still small at just one in 238 (0.42 per cent).

Sophos identified 7,272 new threats during January, bringing the total number of malware protected against to 214,956.

The full list is as follows:

1. Dorf 46.1%
2. Netsky 16.1%
3. Mytob 9.8%
4. Stratio 8.5%
5. Zafi 3.6%
6. MyDoom 2.8%
7. Sality 2.6%
8. Bagle 2.5% 
9. Nyxem 1.0%
10. Wukill 0.8%
Others 6.2%

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Software Programmer/Engineer; C#, Winforms, WPF, WF, WCF, SQL

APPLICANTS MUST BE A EU CITIZEN OR HAVE PERMANENT RESIDENCY...

C# Software Developer; C#, winforms, SQL

C# Software Developer/Programmer/engineer; C#, Winforms...

Linux Administrator / Senior Linux Administrator/ Debian Ubuntu

Linux Administrator / Senior Linux Administrator / Debian...

C#, WPF, Silverlight, UI Development, Software Engineers

C#, WPF, Silverlight, UI Development, Software Engineers...

To send to more than one email address, simply separate each address with a comma.