Welcome | Sign In
LinuxInsider.com
Technology

Spam Fighters Targeted by New Virus

Print Version
E-Mail Article
Reprints
Spam Fighters Targeted by New Virus

"It's become more and more clear that these viruses are professional jobs, and they're done at the behest of spammers," SpamCop founder Julian Haight told TechNewsWorld. "The viruses are intended to break into systems and turn them to the spammer's purpose."


Some folks find flattery in imitation, but spam fighters are finding it in denial-of-service attacks. The attacks are being generated by a nasty but undistinguished virus called Mimail-L, which, as part of its mischief, is commandeering its victims' computers to deluge with e-mail eight prominent antispam sites. The targeted sites include Spamhaus.org, SpamCop.net and SPEWS.org (Spam Prevention Early Warning System) as well as others, such as Disney's Go Web site.

Although the author of the virus has yet to be corralled, spam fighters assert that if you dig deeply enough into Mimail's dark history, you'll find the clammy hand of a vindictive spammer behind the worm -- a spammer who has been burned by the spam busters.

"It's a pat on the back for a job well done as far as I'm concerned," SpamCop founder Julian Haight said of the denial-of-service attacks generated by the malware. "It's annoying, but at the end of the day it tells me I must be doing something right."

Naughty Wendy

According to information posted at the Web site of Sophos, a maker of antivirus and antispam software located in Abingdon, UK, Mimail-L is a worm that spreads using e-mail addresses harvested from the hard drive of an infected computer. The e-mails describe a sexual encounter with "Wendy" and entice the reader of the message to open an attachment containing explicit photos of the exploit.

Once the attachment is opened, the worm is free to poach e-mail addresses. If the infected computer won't send out a message with an attachment, the worm will mail a message without one. That message informs recipients that their credit card will be charged US$22.95 on a weekly basis for a CD of kiddie porn. To cancel that subscription, recipients are advised to send their order and credit card information to the SpamHaus site.

The worm also attempts to turn an infected machine into a relay for sending thousands of spam messages to the eight antispamming sites.

Social Engineering

The major difference between this latest version of Mimail and its predecessors is the "social engineering" aspect of it, Symantec (Nasdaq: SYMC) senior director for security response Sharon Ruckman told TechNewsWorld. "'We are going to bill your credit card' is on the subject line," she explained. "Even if that's spam, it's something most people will want to look at because that makes them nervous."

On a scale of one to five, with five being the most harmful, she said the latest Mimail variant ranks as a Category 2 virus. "It's a more serious threat than a Category 1 would be because it could spread quickly, but it's not a serious enough threat that we're actively notifying the public that they need to be aware of it," she explained.

Buggy Virus

Craig Schmugar, a virus research engineer with McAfee Security, added that there wasn't much that made this variant of the virus stand out from its predecessors. "This one contains some bugs, so the mailing routine isn't as functional as some of the other variants, which is why it hasn't spread as far as some of the other ones," he told TechNewsWorld. "Within the Mimail family alone, this variant has been one of the less successful ones."

"It's become more and more clear that these viruses are professional jobs, and they're done at the behest of spammers," SpamCop's Haight told TechNewsWorld. "The viruses are intended to break into systems and turn them to the spammer's purpose. That can either be hitting us with a denial-of-service attack or actually sending out the spam."

Old Hat

Schmugar, however, noted that Mimail-L doesn't appear to be a professionally created virus. "There have been some press reports recently trying to make the connection between spamming and virus authors, but there are more clear ties in some other viruses than this one," he asserted.

Haight's antispam activity has made him the target of all sorts of Internet attacks. A couple of months ago, for instance, a mass mailing accused him of being an active operative of Al Qaeda. "It's become old hat," he said.


Print Version E-Mail Article Reprints More by John P. Mello Jr.


Related News Alerts

Symantec Activate Alert | Search Archives

More by John P. Mello Jr.

Corel's X3 Photo Editor Paints a Pretty Picture
March 11, 2010
Corel has packed its latest version of PaintShop Photo Pro, X3, with a boatload of new features, many of which are aimed at smoothing out the photographer's workflow. It's tied in a new batch processing feature as well as Express Lab, which gives photo editors the power of combined tools. There's also better support for RAW files and a bonus Painter Photo Essentials 4 app for adding an artistic flourish.
Aperture's Makeover Delights Photogs
March 08, 2010
While Aperture's new features make it more attractive than ever to professional photographers, its main selling point appears to be its superior ability to automate a photographer's workflow. "For me, the most important thing about Aperture -- always has been and remains -- is that it is simply the most powerful archiving tool available," said photographer Bill Frakes.
Mac App Transcribes Speech to Text in a Snap
March 01, 2010
Text-to-speech technology is getting progressively better at recognizing the spoken word, and MacSpeech's latest product, Scribe, throws in transcription as well. Record your words on a portable device, including an iPhone or iPod touch, then hand the audio file over to Scribe. It'll turn it into text in less time than it took you to say it.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network