Storm malware still blowing strong

One year on and no sign of fading away

Written by Clement James

The 2007 Global Threat Report from Bratislava-based security firm ESET has highlighted the huge success of the Storm worm.

The report looked at the social engineering tactics used over the past 12 months and the duration of each technique.

ESET believes that malware authors closely monitor the effectiveness of each ploy in an attempt to aid propagation and infection.

"Storm is a good example of a modern threat that uses advanced technology to infect PCs and maintain its foothold on compromised systems by any means available," said Andrew Lee, chief research officer at ESET.

"It is unique in that its programmers, and the bot-masters they work with, are paying a great deal of attention to maintaining the botnet, releasing frequent updates to evade detection by anti-malware and intrusion detection systems."

A sign of Storm's sophisticated structure and self-updating mechanism is that different components are detected under several different names, even by a single security product.

The Global Threat Report noted that computers running Microsoft's Windows were not the only target during 2007, and that October saw one of the first attacks targeting Apple machines running Mac OS X.

The malware attack targeting OS X resembled W32/Zlob, but was rudimentary compared to cutting-edge Windows malware.

Despite the emergence of more complex threats in 2007, older types of malware such as mass mailers are still circulating in vast quantities.

A sample of 4,251 million emails monitored by ESET from 1 January to 10 December 2007 found that 33.8 million carried malicious content such as a malware attachment or a link to a website containing malicious code.

The most prevalent email-borne threat was malware that closely resembled Win32/Stration.XW (aka Warezov or Stration) which has been around since mid-2006.

Win32/Stration.XW is used to send unsolicited emails and often arrives as an attachment which tries to disguise itself as a normal text file by modifying its own icon.

ESET saw variants of Stration during 2007 that also used MSN Messenger or Skype to send copies of themselves.

See also:

reader comments

related articles

Storm Valentine image

Storm resurfaces for Valentine's Day

Old worm, old trick 17 Jan 2008

 

Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet 10 Jan 2008

Spam levels reach 95 per cent in 2007

Spammers getting more and more inventive 10 Jan 2008

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market 09 Jan 2008

Hackers create new year Storm mutant

'Tis the season to spread malware 02 Jan 2008

The main internet threats for 2008

Mobile malware, botnets, phishing and ID theft 24 Dec 2007

2007 Roundup: The march of the botnets

Top 10 malware list for 2007 24 Dec 2007

Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet 10 Jan 2008

Engate targets botnet protocols

Network profiling allows Engate to block botnet network connections 30 Jun 2008

Storm worm continues its rampage

Botnet makes new spam run, but security companies strike back 04 Mar 2008

latest news

Ingram loses commercial director

Bhavesh Patel set to leave at the end of the month 09 Jan 2009

Ramesys plays IT sheriff of Nottingham

Reseller secures first contract under Primary Capital Programme 09 Jan 2009

Acquisitive Acraman snaps up Ipitomi

Buy-and-build model alive and well as private equity-backed Acraman adds voice specialist Ipitomi to VAR portfolio 09 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation