Storm malware still blowing strong

One year on and no sign of fading away

Clement James

The 2007 Global Threat Report from Bratislava-based security firm ESET has highlighted the huge success of the Storm worm.

The report looked at the social engineering tactics used over the past 12 months and the duration of each technique.

Advertisement

ESET believes that malware authors closely monitor the effectiveness of each ploy in an attempt to aid propagation and infection.

"Storm is a good example of a modern threat that uses advanced technology to infect PCs and maintain its foothold on compromised systems by any means available," said Andrew Lee, chief research officer at ESET.

"It is unique in that its programmers, and the bot-masters they work with, are paying a great deal of attention to maintaining the botnet, releasing frequent updates to evade detection by anti-malware and intrusion detection systems."

A sign of Storm's sophisticated structure and self-updating mechanism is that different components are detected under several different names, even by a single security product.

The Global Threat Report noted that computers running Microsoft's Windows were not the only target during 2007, and that October saw one of the first attacks targeting Apple machines running Mac OS X.

The malware attack targeting OS X resembled W32/Zlob, but was rudimentary compared to cutting-edge Windows malware.

Despite the emergence of more complex threats in 2007, older types of malware such as mass mailers are still circulating in vast quantities.

A sample of 4,251 million emails monitored by ESET from 1 January to 10 December 2007 found that 33.8 million carried malicious content such as a malware attachment or a link to a website containing malicious code.

The most prevalent email-borne threat was malware that closely resembled Win32/Stration.XW (aka Warezov or Stration) which has been around since mid-2006.

Win32/Stration.XW is used to send unsolicited emails and often arrives as an attachment which tries to disguise itself as a normal text file by modifying its own icon.

ESET saw variants of Stration during 2007 that also used MSN Messenger or Skype to send copies of themselves.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet

Spam levels reach 95 per cent in 2007

Spammers getting more and more inventive

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation