'Suicidal Osama Bin Laden' recruits a zombie army

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

A new way of enticing users to open a Trojan horse called Hackarmy was discovered by antivirus firm Sophos on Friday after it was posted on several Internet news groups.

The message claims to contain pictures taken by CNN journalists of Osama Bin Laden's suicide but, once the file is opened, it installs a Trojan horse that effectively recruits the infected machine into the author's zombie army, which can then be used to distribute spam or launch DDoS attacks.

Hackers and virus writers are trying different tricks to try and get people to download their malicious code, said Graham Cluley, senior technology consultant for Sophos.

"It seems this time the hacker has focused on the public's morbid curiosity and appetite for news on the war against terror," he said.

Richard Starnes, president of security industry group ISSA UK, congratulated Sophos for highlighting the issue because it will allow users to "install preventative measures" before the Trojan becomes a widespread.

Malware writers try to get email users' attention and persuade them to open attachments or click on links even if they have been told not to, Starnes said.

"Anna Kournikova, Catherine Zeta Jones and I Love You are all variations of a theme; they are trying to entice the user into doing something they know they often know they shouldn't do," he added.

Antivirus and antispam companies have updated their software to detect the Trojan, according to Starnes, so users need to make sure they have the most recent version of their software.

"It depends on how long [it takes for] antivirus and anti-spam companies [to] respond by releasing new signatures and how quickly the customers respond by downloading and installing them," he said.

Terrorism has been a popular theme amongst malware writers recently. Last week, a variant of the Atak worm was linked with an Al-Qaeda sympathiser who allegedly threatened to release an "uber worm" if the US attacked Iraq.

Talkback

The authors were lambasted on a couple of the Linux newsgroups this morning... Posting information on a Linux newsgroup for a Windows Trojan shows a lot of intelligence *NOT*.

If this is evidence of their logic, it doesn't bode well for the quality of the logic in the code :-)

quoted from Usenet:

>> Osama Bin Ladin was found hanged by two CNN journalists early Wedensday evening. As evidence they took several photos, some of which i have included here. As yet, this information has not hit the headlines due to Bush wanting confirmation of his identity but the journalists have released some early photos over the internet..
>> http://www.theparadise.x-y.net/OsamaFoundDead.zip

I'm having some difficulty getting the backdoor trojan in that link to run. Perhaps you could link directly to the pictures for those of us who run Linux?

via Facebook 24 July, 2004 00:58
Reply

They are at tit again:

The message is as follows (part of the download address has been blacked out):

Arnold Schwarzenegger Commits Suicide

Early this morning Arnold Schwarzenegger was found hanging by his neck from the large oak tree in his Californian garden. In a suicide note found at the scene he tells of his sordid sex life and lack of will to live. A copy of the suicide note which was found by journalists has been included here
http://wwwXXXXXXXXXXXXt/ArnoldSchwarzenegger.zip

via Facebook 24 July, 2004 15:49
Reply

i think this should be dubbed the suicide virus. just today i found the virus again as arnold Schwarzenegger committing suicide.
i believe i was able to save myself, even after falling for the osama trap, i was torn between suspicion and curiosity. curiosity won, luckily my sygate firewall (which is free, and in my opinion the best ive seen) was able to block the new generic host process 32 it started, and was able to identify the new service and , keep it from starting this is the start up item i remove from my registry, hope this helps others, i used "regcleaner 4.3"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Winsock32driver"="ZoneLockup.exe"
im still not sure if im totally safe though
if anyone else has more information please post it, thanks

via Facebook 24 July, 2004 15:53
Reply

Hey German IT consultant.
Try running it under Wine :D

You other people who downloaded it. Gimme a break! Are you really that dumb ?

Usenet suffers from another poster who keeps posting supposed "Sister caught..." and "sister and mother" and other rubbish purporting to be underage porn where the file extention is .scr (screensaver). Don't be a muppet! Don't download it!
I have a usenet filter. I guess I'm going to add the word "suicide" to it :P

via Facebook 25 July, 2004 21:06
Reply

I saw this on Usenet and figured it was something dodgy. Out of curiosity I looked at Google groups and they had it filtered from their messages straight away which I thought was pretty good going.

via Facebook 26 July, 2004 15:07
Reply

I too saw the Arnold version. It was on saturday morning and I found it throughout all of the tech group sites at microsoft. There were multiple entries in all of the headings. Most of them were from east coast colleges. The thing that clued me in was the .zip extension at the end of the website address in the link that was provided for reading the article. Sounded like a self unzipping exicutible would run once connected to the site.
Later in the day all of these messages had been removed.

via Facebook 26 July, 2004 17:16
Reply

The Arnie one has been removed.
I don't know about the Osama one - I think it
was being hosted from a US broadband IP address.
I actually did a domain lookup and told the administrative contact about the Arnie one, so who knows - it may even have been my email that made it disappear... maybe if you see something stupid like this you should be proactive and report it :D
The sky is not falling!

via Facebook 26 July, 2004 19:20
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

7 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

17 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

17 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

21 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

22 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

23 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

24 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint