ZDNet:  Reviews | Downloads | Tech Update | Prices
Page OneApplicationsNetworkingeBusinessHardwareCommentary



Networking


E-mail virus alert spreads worm
By Robert Lemos
Special to ZDNet News
November 11, 2002, 4:36 AM PT


TalkBack!


A Russian antivirus company apologized Friday for an e-mailed virus alert that was infected with the very worm the message was supposedly designed to warn against.

Kaspersky Labs said the message, sent Thursday to subscribers of the company's "Virus News" e-mail dispatch, had actually been sent by hackers masquerading as the company. The hackers had managed to break into Moscow-based Kaspersky's computer system and steal the mailing list for the newsletter, the company said.

"We are conducting an investigation to reveal the sources of this attack and are taking the necessary measures...to ensure that this type of attack will never succeed in the future," Eugene Kaspersky, founder and head of research for the company, said in an advisory about the e-mail.

Click Here.

To date, the company hasn't heard of any infections resulting from the tainted message, but it has offered free technical services to anyone who does fall prey to the viral prank.

The infected message, sent to some thousands of subscribers, carried a copy of the recently discovered Braid worm.

Braid, also known by Kaspersky Labs as Bridex, hasn't spread very widely. U.K.-based e-mail service provider MessageLabs intercepts such hostile attachments for its client companies and has seen only a little more than 2,000 copies of the virus in the last 24 hours. That places the malicious program at No. 5 on MessageLab's daily Top 10 list; the Klez virus leads the pack with over 9,000 infected e-mails intercepted by the company in the last 24 hours.

A variant of the FunLove virus, Braid is written in Visual Basic Script and has its own e-mail engine. That means it can spread itself even if a victim's computer doesn't have an e-mail client such as Outlook installed. The virus infects computers running on Windows, makes several copies of itself on the hard drive, searches for e-mail addresses in a variety of files and then sends itself out to those addresses.

But Thursday's mass mailing of the virus wasn't the result of an infection, said Denis Zenkin, director of marketing for Kaspersky Labs. It was a deliberate act by online vandals.

"Some hackers got into our Web server and got the addresses of our subscribers," Zenkin said, "and these hackers sent a message with the Bridex worm to all of the subscribers."

Zenkin said he doesn't know how the hackers infiltrated the Web server, which ran the Unix variant FreeBSD and the mail program Postfix.

However, he did say such attacks are no longer a rare occurrence, especially in Russia.

"We get dozens and dozens of attacks every day," Zenkin said, trying to put a positive face on the whole incident.

"This case shows that Kaspersky Labs is growing and becoming more and more famous and attracts more attentions from the hackers," Zenkin said.


E-mail this story! Printer Friendly

Also on ZDNet
Find the tech gear you need in CNET's Back to School guide.
Get ahead of the competition with the BizTech Library.
Improve your PC's performance with the Memory Configurator.
Don't miss up-to-the-minute IT commentary on TechRepublic's blog.
Laid off? Find a new IT job today in our Career Center.


 TalkBack: Post your comment here
       Re: E-mail virus alert spreads worm  Loverock Davidson

       simple solution:turn off scripting  pinner blinn

       Re: E-mail virus alert spreads worm  Richard Mooney



 Search


 
 Tech Update

Five steps to secure mobile data

DriveSavers recovers critical data

Microsoft earns security badge

More networking analysis...

 News in Brief

Tablet PCs finding few takers in Singapore  09:28AM

National Semi, ARM to extend cell phone battery life  08:24AM

Silicon Valley unemployment on the rise  07:37AM

Sonicblue, TiVo settle patent spat  05:50AM

Mattel loses cybersquatting challenge  04:15AM

More...

 Commentary

CASTAGNA CASTAGNA
Tech Update's Executive Editor looks at wireless, mobile apps and more. More...

More Commentary...


ZDNet Tech Update
Featured Resource Centers
Sybase:
Request for more info, Whitepapers and more.
Gateway:
Hardware, Products and more.

 News Tools

 News Archives

 News in Brief

 News for your PDA

 Contact Us

 Corrections
Newsletters
Tech Update Today
Security Update
OS Update




All newsletters
FAQ
Manage my newsletters


ZDNet
Services: Bandwidth Test | BizTech Library | Holiday Gift Guide | Home Office PC Tips | Tech Jobs

      CNET Networks: Builder | CNET | GameSpot | mySimon | TechRepublic | ZDNet
About CNET Networks 

About Us | Support | Your Privacy | Service Terms | Advertise | ZDNet Jobs 
 
Copyright © 2002 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc.