Computer virus
Hackers are releasing new versions of Mytob all the time

Mytob variant hides sting in the tail

Devious new trick to fool the unwary

Robert Jaques

IT security experts today warned that mutant versions of the Mytob worm more virulent than its predecessors are spreading rapidly across the internet.

Hackers are releasing new versions of Mytob all the time, according to security firm Sophos, and different variants currently account for 14 of the top 20 most commonly reported viruses to the firm in the past seven days.

Advertisement

Researchers have revealed that some of the new variants use a different method to try and infect unsuspecting users.

Whereas most Mytob worms arrive in an email with a virus attachment, the latest versions adopt a trick most commonly used by phishers: a faked web link pointing to the malicious code.

Clicking on the link will not visit the domain name that is claimed, but takes users to a different website where the worm is automatically downloaded.

Emails sent by these mutant versions of Mytob masquerade as a seemingly legitimate email from an organisation's IT department or ISP, and suggest to users that a security problem has been found with their email account.

Users are advised to click on the web link to confirm their account. In a crafty twist, references are made to the recipient's domain name and email address to give the message more legitimacy.

The new versions of Mytob contain a number of hidden messages. For instance, some claim the author's name as 'DiablO" and contain debug strings such as '[x] starting Hellbot::v3 beta 2'.

"By using this disguise, new versions of Mytob attempt to lure the unwary into clicking on a dangerous web link," said Graham Cluley, senior technology consultant at Sophos.

"This is a real headache for IT departments which often struggle to get their users to follow instructions. In this case, following the advice of the email would be a very bad idea."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation