Worm warfare rages on

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The recent surge in worms could be part of an underground battle to hijack PCs for use in Net crimes, some security experts say — but others aren't convinced.

Signs of a turf war between cybercriminals lie in the behaviour of the worms that have emerged since Sunday, said Mikko Hyppönen, chief research officer at security firm F-Secure.

The dozen or so worms and variants all exploit a security hole in the plug-and-play feature in the Windows 2000 operating system. But some versions undo the effects of earlier worms, suggesting that the creators are battling to take over computers that others have already compromised, Hyppönen said.

"We seem to have a botwar on our hands," Hypponen said on Wednesday. "There appear to be three different virus-writing gangs turning out new worms at an alarming rate, as if they were competing to build the biggest network of infected machines."

The first worm, dubbed Zotob, appeared on Sunday and appeared to have faded on Monday. However, several Zotob offshoots and another new worm, Bozori, were subsequently unleashed. New versions of pre-existing threats Rbot, Sdbot, CodBot and IRCBot also began wriggling their way into computers. Systems at CNN, ABC and The New York Times were hit.

The worms include "bot" code, or a program that lets the attacker control a compromised system remotely. Criminals have typically organized these hijacked systems in networks called botnets. These botnets are rented out to relay spam and launch phishing scams which attempt to steal sensitive personal data for fraud. Botnets have also been used to mount DoS attacks against online businesses targeted by extortion schemes, experts have said.

The outbreak has a financial motive, according to British antivirus firm Sophos. "Organised criminal gangs are behind attacks like these, and their motive is to make money. Owning a large network of compromised computers is a valuable asset to these criminals," said Graham Cluley, the senior technology consultant at Sophos.

A botnet of about 5,500 zombies, or compromised computers, typically costs spammers, phishers or other crooks about $350 a week, security company Symantec has said.

The worm battle has likely only just begun, said Alex Shipp, a senior antivirus technologist at MessageLabs, an email security company. He said we may well see a period of intense activity in malicious software attacks as these groups vie for "pole position."

Battling worms are not new. Last year, the creators of Bagle, Netsky and MyDoom appeared to be in competition to gain control of large numbers of PCs for use in botnets.

But not everybody is convinced that the same kind of turf war is happening now. Stefana Ribaudo, a director in the threat management sector at Computer Associates, said the company had not seen any viruses or worms that try to detect or remove other worms.

Lysa Myers, a virus research engineer at security software maker McAfee, agreed that there were no real signs of a struggle to control botnets. "This particular worm outbreak is so small that there really is no room for an offensive strategy," she said.

If there is anything going on, it is just an underground rivalry, said John Pironti, a principal security consultant at Unisys, an IT services company. "Attackers like to boast about how many machines they have under their control," he said. "What you are potentially seeing is that it is a contest."

If the purpose was really to expand botnets, attackers would use more sophisticated methods that fly under the radar of antivirus companies, Pironti said.

Microsoft offered a fix for the Windows plug-and-play bug exploited by the worms in its monthly patching cycle last week. The software maker deemed the issue "critical", its most serious rating. The first Zotob variant appeared in record time after Microsoft's patch release, giving Windows users little time to fix their systems.

The security issue affects Windows XP and Windows Server 2003, but only PCs running Windows 2000 are susceptible to a remote attack, Microsoft has said.

There are desktop and server versions of Windows 2000, which was released in 2000 for business users rather than consumers. More recent editions of Windows are available, but Windows 2000 remains popular. The operating system ran on 48 percent of business PCs during the first quarter of 2005, according to a recent study by AssetMetrix.

Infected machines can be cleaned up using tools available from antivirus software makers, including Symantec. Windows 2000 users who have not patched should do so as soon as possible, Microsoft has urged.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

40 minutes ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

4 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

5 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

11 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

13 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

15 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

15 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

16 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

17 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

18 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

18 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

18 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

18 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

21 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA