Storm worm strikes again on Easter claiming Iran attack

Security researchers discovered a spate of new variants of the Storm worm making the rounds this weekend through emails reporting fictitious news of the United States attacking Iran.

The scam emails on the loose include mangled subject lines, such as "USA Just Have Started World War III,” "Missle Strike: The USA kills more then 20000 Iranian citizen," "Israel Just Have Started World War III" and "USA Missile Strike: Iran War just have started" — all with malicious programs with enticing names such as “movie.exe.”

According to Adam O’Donnell, senior research scientist with Cloudmark, the latest analysis of the malicious binaries showed that they are variants of the storm worm that first made its big splash with millions of infections in January.

“This is the exact same thing,” he said. “The attackers use a methodology where they send out an executable attachment associated with some kind of major news story, or fictitious news story, to get people interested enough to load up the virus.

When the virus is installed, it creates a peer-to-peer network. Most of the attackers are interested in setting up spam-sending networks, which is most likely the purpose of this variant as well.”

The analysis by the Cloudmark team found that 12 main variants were sent in a blitz that began on Sunday morning.

“I would be surprised if that was unintentional,” he said, explaining that the professional hackers probably hoped to take advantage of the fact that most security researchers would be with their families. “These guys know how to make money.”

The tactic worked, O’Donnell said, explaining that it took 24-hours for most of the major anti-virus (AV) vendors to respond to the attacks. He questioned the speed, wondering why the vendors didn’t create more versatile signatures for the worm when the first wave hit systems in January.

“You would think after that episode, the traditional AV organizations would be a little more proactive about writing generic signatures to catch this kind of attack,” he said. “But that apparently wasn’t the case.

The true issue is that AV organisations are structured to combat the threat of a teenager in the basement, but nowadays we face what I like to call a unified threat horizon created by the criminal underground.”

Storm worm strikes again on Easter claiming Iran attack

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read