Thanksgiving will bring a Sober hangover

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The latest outbreak of the Sober worm will accelerate as US computer users turns the PCs back on after the Thanksgiving holiday, security firm MessageLabs warned on Friday.

Business users will return from the break and open mail that has been sitting in their inbox since the first hours of the attack, which could include infected emails, MessageLabs warned.

Sober-Y spreads in emails that pretend to come from the FBI or which claim to contain video clips of celebrity heiress Paris Hilton. It is activated if the user runs an email attachment.

"Once this worm has been activated behind a firewall, it's very difficult to identify, as most firewalls don't inspect outbound data traffic." said Paul Wood, senior analyst at MessageLabs.

Businesses may also be suffer if their mail servers are swamped by email traffic caused by infected home users.

"Businesses may suffer collateral damage due to the volume of mail hitting people's mailservers. Even secure business servers may be affected, as spam still consumes bandwidth before it can be rejected," said Wood.

This week's Sober attack is the largest that MessageLabs has seen in 2005. "This is the biggest outbreak of a mass-mailing virus all year. It is a concern because we thought we'd seen the last of mass-mailers," said Wood.

Experts at antivirus company Sophos also see Sober-Y as a major threat. Globally, one in 18 emails are now infected by the Sober worm, Sophos said on Friday.

"The new Sober worm is spreading at such a rate that it now accounts for over 80 percent of all viruses reported. It is currently the most widespread computer virus in the world," said Graham Cluley, Sophos' senior technology analyst.

If activated, Sober-Y attempts to turn off security software on the user's computer. The zip file in the attachment contains a copy of the worm with the filename File-packed_dataInfo.exe. The worm then scans the user's hard drive for other email addresses, in its search for other computers to infect, Sophos said.

MessageLabs believes Sober-Y could continue to spread in large quantities for some time, as the auto switch-off function used in most mass-mailing malware hasn't been enabled.

"Normally you would see an auto switch-off function included in the code, because controllers don't want to draw too much attention to their botnets — so there's a cut-off date, and the outbreak stops. We haven't seen a cut-off date in this Trojan, so this outbreak could continue for some time," said Wood.

This outbreak is likely to be financially motivated. MessageLabs believes that cybercriminals may be trying to increase the number of compromised computers they have access to before Christmas, for financial gains.

"We believe botnet controllers are bolstering their botnets before Christmas, to sell access to spammers," said Wood.

The source code for Sober originated in Germany, but is now being used by Eastern European criminal gangs, said MessageLabs.

IT managers were advised to actively monitor their outbound email traffic for evidence that they have been infected by Sober-Y, and not just rely on a firewall. "It's certainly a challenge for organisations to control email traffic just by using a firewall. IT managers can manage this particular outbreak by protecting HTTP and SMTP traffic," said Wood.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

2 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

10 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

12 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

12 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

17 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

18 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

18 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

19 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

20 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint