Conficker worm dabbling with mischief
April 28, 2009 by Glenn Chapman
A man downloads a patch from Microsoft's web site to protect his computer from a worm virus. The Conficker worm's creators are evidently toying with ways to put the pervasive computer virus to work firing off spam or spreading rogue anti-virus applications called "scareware."
The Conficker worm's creators are evidently toying with ways to put the pervasive computer virus to work firing off spam or spreading rogue anti-virus applications called "scareware."
An April update sent to a tiny percentage of infected computers had the machines retrieve components of notorious Storm and Waledac worms unleashed in past years to create armies of "botnets" -- automated crime networks -- for spreading spam or scareware.
"It looks like these guys are perhaps testing the waters to see which one of those would be a better money-maker for them," Trend Micro advanced threats researcher Paul Ferguson said Monday of Conficker's masters.
"We have always suspected that the people behind this would not sit idly by without trying to make money off this somehow. Spamming and rogue anti-virus are pretty lucrative for these guys."
Ties to components of Storm and Waledac signal that Conficker's creators were likely involved with the other computer worms, according to security specialists.
"This connects the dots that the same people behind Conficker are the people behind Waledac and Storm," Ferguson said, noting that evidence is pointing to an organized hacker enterprise in the Ukraine.
"These are well-funded organized cyber-criminals in Eastern Europe. They want to steal people's money out of their pockets without being noticed. This same criminal operation is very business savvy."
Hackers are increasingly hiding viruses in bogus computer security software to trick people into installing treacherous programs on machines, Microsoft warned earlier this month.
Rogue security software referred to as "scareware" pretends to check computers for viruses, and then claims to find dangerous infections that the program will fix for a fee.
"The rogue software lures them into paying for protection that, unknown to them, is actually malware offering little or no real protection, and is often designed to steal personal information," Microsoft said.
Hackers have been capitalizing on hype and fear surrounding Conficker to trick people into loading scareware onto computers.
A task force assembled by Microsoft has been working to stamp out Conficker, also referred to as DownAdUp, and the software colossus has placed a bounty of 250,000 dollars on the heads of those responsible for the threat.
The worm, a self-replicating program, takes advantage of networks or computers that haven't kept up to date with security patches for Windows.
It can infect machines from the Internet or by hiding on USB memory sticks carrying data from one computer to another.
Conficker could be triggered to steal data or turn control of infected computers over to hackers amassing "zombie" machines into "botnet" armies.
Ferguson believes Conficker's creators are out for cash, not wanton destruction, but that the worm's spread is a sobering reminder that botnets could be turned against Internet-linked parts of national infrastructures.
"How do you rationalize connecting critical networks to the Internet when those kinds of attacks are possible?" Ferguson asked rhetorically.
"We used to joke that the only guarantee for 100 percent security is a pair of wire cutters."
(c) 2009 AFP
-
Bogus security software growing threat: Microsoft
Apr 08, 2009 |
not rated yet |
0
-
Conficker worm plays no tricks on April Fools' Day
Apr 02, 2009 |
not rated yet |
0
-
Conficker worm digs in around the world
Apr 01, 2009 |
not rated yet |
0
-
Huge computer worm Conficker stirring to life
Apr 09, 2009 |
not rated yet |
0
-
New homeland security tool to detect Conficker worm
Mar 30, 2009 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Need help reading 3-D
8 hours ago
-
A way to send and receive wireless data
14 hours ago
-
Tabletop Cold Fusion Reactor
15 hours ago
-
Calling function with no input argument
Feb 10, 2012
-
Force free body diagram problem on gym equipment
Feb 10, 2012
-
Empirical data regarding shower heads and water
Feb 10, 2012
- More from Physics Forums - General Engineering
More news stories
Walney offshore wind farm is world's biggest (for now)
(PhysOrg.com) -- The Walney wind farm on the Irish Sea--characterized by high tides, waves and windy weather--officially opened this week. The farm is treated in the press as a very big deal as the Walney ...
GPS court ruling leaves US phone tracking unclear
A US Supreme Court decision requiring a warrant to place a GPS device on the car of a criminal suspect leaves unresolved the bigger issue of police tracking using mobile phones, legal experts say.
17 hours ago |
4 / 5 (2) |
0
Europeans protest controversial Internet pact
Tens of thousands of people marched in protests in more than a dozen European cities Saturday against a controversial anti-online piracy pact that critics say could curtail Internet freedom.
13 hours ago |
4.5 / 5 (8) |
0
Netflix settlement trims 14 pct off 4Q earnings
(AP) -- Netflix pressed the rewind button on its fourth-quarter earnings after settling allegations that the video subscription service violated a consumer-privacy law.
17 hours ago |
not rated yet |
0
Navy to begin tests on electromagnetic railgun prototype launcher
The Office of Naval Research (ONR)'s Electromagnetic (EM) Railgun program will take an important step forward in the coming weeks when the first industry railgun prototype launcher is tested at a facility ...
Feb 06, 2012 |
4.7 / 5 (15) |
92
|
Europe stakes billion-dollar bet on new rocket
A pencil-slim rocket is scheduled to lift into space from South America on Monday, carrying a billion-dollar bet that Europe can grab a juicy slice of the market to place satellites in low orbit.
Study finds that anti-diabetic medication can prevent the long-term effects of maternal obesity
In a study to be presented today at the Society for Maternal-Fetal Medicine's annual meeting, The Pregnancy Meeting, in Dallas, Texas, researchers will report findings that show that short therapy with the anti-diabetic medication ...
Explained: Sigma
It's a question that arises with virtually every major new finding in science or medicine: What makes a result reliable enough to be taken seriously? The answer has to do with statistical significance -- but ...
Political leaders play key role in how worried Americans are by climate change: study
More than extreme weather events and the work of scientists, it is national political leaders who influence how much Americans worry about the threat of climate change, new research finds.
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
NASA budget will axe Mars deal with Europe: scientists
US President Barack Obama's budget proposal to be submitted next week for 2013 will cut NASA's budget by 20 percent and eliminate a major partnership with Europe on Mars exploration, scientists said Thursday.
Apr 28, 2009
Rank: 5 / 5 (1)
Could be fun to watch, from a safe distance of course:P.
Apr 28, 2009
Rank: 2.3 / 5 (3)
Well, I certainly have not kept up to date with security patches for Windows and I'll never do.
As well, I'm not in need neither of bogus computer security software nor of regular computer security software.
It depends which operating system you choose. And the choice is yours.
Apr 28, 2009
Rank: 3.7 / 5 (3)
Apr 28, 2009
Rank: not rated yet
Concerned about "companies cutting the wire". I wouldn't like that at all. Stupid kids.
Apr 28, 2009
Rank: 2.3 / 5 (3)
That's the theory.
In RealLife reality counts more than theory. Theoretical malign software doesn't bother my OS. Real malign software doesn't exist for my OS.
Call it pragmatism.
Apr 28, 2009
Rank: not rated yet
Apr 28, 2009
Rank: 1 / 5 (1)
I'd love to - it would make me famous in my community.
May 03, 2009
Rank: not rated yet
1) everyone will target the OS you run (why waste time on only a small fraction of potential targets?);
2) the company that sells your OS will have a stake in protecting you (who gets the bad publicity?)
If you family runs multiple Windows PCs, look seriously at Microsoft's OneCare (onecare.com). I find it excellent on both XP and Vista platforms. It is cheap protection if you run multiple PCs on broadband Internet (less than $17 per PC per year.)