Search:
Go!


'Storm Worm' rages across the globe

Mass-mailed Trojan horse baits people with timely information about a deadly, real-life storm front in Europe.
By Dawn Kawamoto
Staff Writer, CNET News.com
Published: January 19, 2007, 8:15 AM PST
Last modified: January 19, 2007, 10:00 AM PST

update "Storm Worm," one of the larger Trojan horse attacks in recent years, is baiting people with timely information about a deadly, real-life storm front, security researchers said Friday.

Over an eight-hour period Thursday, malicious e-mails were sent across the globe to hundreds of thousands of people, said Mikko Hypponen, chief research officer for F-Secure.

People who open the attachment then unknowingly become part of a botnet. A botnet serves as an army of commandeered computers, which are later used by attackers without their owners' knowledge.

Storm Worm carries the subject line "230 dead as storm batters Europe," Hypponen said, noting the unusual twist to the e-mail.

"The e-mail was started 15 hours ago, when the storm was peaking in Central Europe," Hypponen said. "This is unusual in that it was very timely."

Storm Worm is a Trojan horse with an executable file as an attachment. Cybercriminals took advantage of social engineering, using the news of the European storm to get people to open the attached malicious file, which promises more news on the weather emergency. The recipient must open the file for it to execute.

The file creates a back door to a computer that can be exploited later to steal data or to use the computer to post spam.

Storm Worm is already close to being as large as the bigger attacks of 2006, Hypponen said, though it's still smaller than Sasser and Slammer.

Hypponen also noted that this Trojan horse is unusual because most attacks these days tend to be smaller and targeted, as criminals seek to pilfer personal information for financial gain, rather than fame.

Though Storm Worm is widespread, the damage may ultimately be minimal in the U.S. because most tech security companies will have already added it to their blocking list before people get into work, he added.

Other e-mail subject lines for it include "U.S. Secretary of State Condoleezza..." and "A killer at 11, he's free at 21 and..."

According to the Associated Press, the European storm has killed at least 41 people.

Read more on this story's topics and companies

 32 comments
Post a comment

TalkBack

Internet Common Sense 101

wbenton 
Jan 23, 2007, 7:06 AM PST

Letter to the writer of this article...

lkrupp 
Jan 22, 2007, 4:23 PM PST

LOL

sea_net 
Jan 22, 2007, 6:48 AM PST

Cnet is afraid

clsgis 
Jan 21, 2007, 9:42 AM PST

Macs weather the storm..!!

imacpwr 
Jan 20, 2007, 4:20 AM PST

Not about bragging rights

RoutinelyCalled 
Jan 19, 2007, 10:35 AM PST

lol

sal-magnone 
Jan 19, 2007, 9:55 AM PST

And of course....

J_Satch 
Jan 19, 2007, 5:30 AM PST

What platform?

rbannon 
Jan 19, 2007, 5:16 AM PST

advertisement

Markets

Market news, charts, SEC filings, and more

Related quotes

DJIA 12,533.80 56.64 (0.45%)
S&P 500 1,427.99 5.04 (0.35%)
NASDAQ 2,431.41 0.34 (0.01%)
CNET TECH 1,600.26 -2.85 (-0.18%)
  Symbol Lookup
advertisement


Copyright ©2007 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use