Welcome | Sign In
LinuxInsider.com
Security

Funner Worm Spreads to US

Print Version
E-Mail Article
Reprints
Funner Worm Spreads to US

Symantec said when someon clicks on an infected link in a message, the worm tries to download code from remote sites, to redirect users to certain Web sites and to send a version of itself to everyone in an IM user's contact list as well. Symantec reported fewer than 50 infections of the worm in the U.S. as of midday today.


Security companies have identified a new worm spreading through Microsoft's (Nasdaq: MSFT) instant messaging platform.

The worm, known as the Funner worm, originated in Asia but is quickly spreading to the U.S., according to instant messaging security firm IMLogic.

The worm has only been spotted to date on the Microsoft IM platform, MSN Messenger. However, Microsoft said that it is not related to an outage of that service, which was unavailable for some time yesterday, according to a company spokesperson. The company said a problem with scheduled maintenance appears to be the cause of the downtime.

Security firm McAfee said the risk to both home and corporate users is "low," while Symantec (Nasdaq: SYMC) antivirus termed the worm a "nuisance."

Symantec said when an infected link in a message is clicked, the worm attempts to download code from remote sites, to redirect users to certain Web sites and to send a version of itself to everyone in an IM user's contact list as well. The firm reported fewer than 50 infections of the worm in the U.S. as of midday today.

Tip of the Iceberg?

Still, while the current worm's threat was being downplayed, security firms were quick to add that a sophisticated blended threat sent through IM could pose significant security threats.

Sophos antivirus consultant Graham Cluley said that, like a much earlier version of FunnyFile worm, first spotted more than two years ago, the current worm is not an urgent threat, but does serve as a reminder that the instant messaging platforms represent a potential backdoor into enterprises that staunchly guard their e-mail gateways.

"Companies may spend enormous resources to guard against e-mail borne worms, but if their employees are downloading and using IM, there can be an entirely new threat they're not prepared for," Cluley said.

Fair Warning

Cluley and other security experts say the arrival of the Funner worm and the strong likelihood that more powerful copycat versions will follow are good reasons to draft and enforce policies against unauthorized downloading and use of IM products except those sanctioned by a corporation or network administrator.

Ken Dunham, director of malicious code at iDefense, said IM worms have been a growing area of concern, even though no devastating threat has yet emerged.

"We have more and more people using it and we also have increased interoperability, which raises the risk of a single worm infecting different platforms," Dunham told the E-Commerce Times. "The greatest threat would be if someone put together an all-in-one virus that works in all IMs or targeted one of the most popular with a powerful code."

Dunham said that from a social engineering perspective, IM has the potential to spread network worms or other malicious code even more effectively, because of its instant nature. "It pops up as a message from a trusted friend and you might tend to be more inclined to follow a link to a Web site," he said.

"We haven't seen anything terrible yet, but there is certainly potential in the IM world," Dunham added.


Print Version E-Mail Article Reprints More by Keith Regan


Talkback: Join the Discussion.
Re: Funner Worm Spreads to US
micahfk
Posted 2004-10-14
It's a little more dangerous than that. The program seems to have a built-in response to Norton ...

More by Keith Regan

Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense
June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales
June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive
June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network