On The Insider: Sexy Aussie Babes
BNET Business Network:
BNET
TechRepublic
ZDNet

By Colin Barker, News.com
Posted on ZDNet News: Aug 22, 2006 9:31:00 PM

Malicious code that exploits a recent Windows hole has led to significant growth in the number of hijacked PCs, according to messaging security company CipherTrust.

On Tuesday, CipherTrust reported a 23 percent growth in the total number of so-called zombie PCs it has detected. The jump is due to the spread of Mocbot worm variants, CipherTrust said. Mocbot, also known as Cuebot and Graweg, exploits a Windows security flaw for which Microsoft issued a patch with security bulletin MS06-040 on Aug. 8.

"Around Aug. 13, the weekend after Black Tuesday, we started seeing a gradual increase in the average number of new zombies," said Dmitri Alperovitch, a research scientist at CipherTrust in Alpharetta, Ga. "It went up from 214,000 every day in the previous week to 265,000 every day."

Any computer infected by Mocbot will become part of a botnet, a large network of compromised PCs that can be controlled remotely to carry out tasks such as sending spam. In June, Microsoft warned that the threat posed by botnets and zombies was growing fast.

CipherTrust can trace the increase in spam-sending zombies to Mocbot by comparing junk e-mail sent by systems it knows were compromised by the worm to the spam sent by new zombies, Alperovitch said. "They are mostly Rolex spam and porn spam, and they are the same messages that are being sent by these new zombies coming online," he said.

Alperovitch estimated that somewhere between 500,000 and 1 million machines were hijacked by Mocbot. As a result, more junk mail is soiling the Internet, with spam making up 81 percent of all mail volume this week. "I would not say this has been a huge outbreak, but it has been a noticeable change," he said.

Security experts had said that the MS06-040 worm appeared to be limited in its spread and only hitting computers running Windows 2000.

Colin Barker of ZDNet UK reported from London.

Malicious code that exploits a recent Windows hole has led to significant growth in the number of hijacked PCs, according to messaging security company CipherTrust.

On Tuesday, CipherTrust reported a 23 percent growth in the total number of so-called zombie PCs it has detected. The jump is due to the spread of Mocbot worm variants, CipherTrust said. Mocbot, also known as Cuebot and Graweg, exploits a Windows security flaw for which Microsoft issued a patch with security bulletin MS06-040 on Aug. 8.

"Around Aug. 13, the weekend after Black Tuesday, we started seeing a gradual increase in the average number of new zombies," said Dmitri Alperovitch, a research scientist at CipherTrust in Alpharetta, Ga. "It went up from 214,000 every day in the previous week to 265,000 every day."

Any computer infected by Mocbot will become part of a botnet, a large network of compromised PCs that can be controlled remotely to carry out tasks such as sending spam. In June, Microsoft warned that the threat posed by botnets and zombies was growing fast.

CipherTrust can trace the increase in spam-sending zombies to Mocbot by comparing junk e-mail sent by systems it knows were compromised by the worm to the spam sent by new zombies, Alperovitch said. "They are mostly Rolex spam and porn spam, and they are the same messages that are being sent by these new zombies coming online," he said.

Alperovitch estimated that somewhere between 500,000 and 1 million machines were hijacked by Mocbot. As a result, more junk mail is soiling the Internet, with spam making up 81 percent of all mail volume this week. "I would not say this has been a huge outbreak, but it has been a noticeable change," he said.

Security experts had said that the MS06-040 worm appeared to be limited in its spread and only hitting computers running Windows 2000.

Colin Barker of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 81 Talkback(s)
Been running LUA for years now...
Amazing how well it works so far. But then, the vulnerability being discussed will nail you no matter what security level you are running on Windows XP/Server 2003. And if you are running Linux, the s... (Read the rest)
Posted by: Boomslang Posted on: 08/27/06 You are currently: Logged In | Log out
Worm Sparks Rise In Zombie PCs itanalyst   | 08/22/06
I give you a seven for trying ,,, Intellihence   | 08/22/06
worms...etc. ohaspider   | 08/22/06
unfortunately there already is alandee4   | 08/23/06
um..... Suicida|   | 08/23/06
sender and domain fake, why not rply-to? Still Lynn   | 08/23/06
The heading of this story should read" Worm sparks rise in MS zombie PCs . Intellihence   | 08/22/06
How bout "Worm sparks rise in UNPATCHED zombie PCs" PB_z   | 08/22/06
How bout "Worm sparks rise in UNPATCHED MS zombie PCs" Intellihence   | 08/22/06
garbage posts steveh99   | 08/23/06
Plain ignorance of Different OS Architectures LinuxUser&XPGamerGraphic   | 08/23/06
Not completely true rpmyers1   | 08/24/06
MAC attack ! chuck@...   | 08/23/06
That is an opinion from a non-technical user. LinuxUser&XPGamerGraphic   | 08/23/06
Not News Kobashrer   | 08/22/06
hah kielork   | 08/23/06
Worm sparks rise in zombie PCs Loverock Davidson   | 08/22/06
...home users have autoupdate on... swoopee   | 08/23/06
Really Loverock Davidson   | 08/23/06
and what about... vmtnezgil@...   | 08/23/06
What about them? Loverock Davidson   | 08/23/06
The point is ISP or subscriber responsability? vmtnezgil@...   | 08/23/06
I may be wrong swoopee   | 08/23/06
Auto Update not a panacea MacCanuck   | 08/23/06
Autoupdate works fine Loverock Davidson   | 08/23/06
In your dreams :-) MacCanuck   | 08/23/06
Dreams turn into reality Loverock Davidson   | 08/23/06
Considering people's reliance on the Internet MacCanuck   | 08/23/06
Your own comments about Updates slim-01   | 08/23/06
Administrators, or MS? rpmyers1   | 08/23/06
Correction: Ed Bott's article rpmyers1   | 08/23/06
All is hopeless Carrion   | 08/23/06
Hmm Krazyken39   | 08/23/06
fascinating... Carrion   | 08/23/06
Do you even use Linux? slim-01   | 08/23/06
On the nose! handydan918   | 08/23/06
Hope you have better luck than I do... LuckyCharm   | 08/23/06
It's not hopeless, but it IS a pain ... kennedym@...   | 08/23/06
Been running LUA for years now... Boomslang   | 08/27/06
MS Champs at breaking their OS, cant say crap w/mouthful jonathan swift   | 08/23/06
The only victims ctm66446   | 08/23/06
So true on so many points, Boot_Agnostic   | 08/23/06
Reality..... john_galt@...   | 08/23/06
And this makes you superior because? orangemike   | 08/23/06
Just not in that group ctm66446   | 08/23/06
Bull Boot_Agnostic   | 08/24/06
And do what with it... ctm66446   | 08/24/06
It makes a wonderful fallback Boot_Agnostic   | 08/24/06
The Windblows at Microsucts This501   | 08/23/06
how does it not work? ctm66446   | 08/23/06
your money steveh99   | 08/23/06
Put "Bottom Line" in First Paragraph! archetuthus   | 08/23/06
i agree with you ctm66446   | 08/23/06
Worm Compromised PC's zeghost@...   | 08/23/06
Charge for each email! meperr8@...   | 08/23/06
Charge for each mail mebejb   | 08/23/06
Church of the Painful OS Reverend MacFellow   | 08/23/06
Amen, brother! orangemike   | 08/23/06
What of the Mac resurrection? oldradiojock   | 08/23/06
Server side or client side? vmtnezgil@...   | 08/23/06
ISP's john_galt@...   | 08/23/06
thought? vmtnezgil@...   | 08/23/06
I don't want to pay my ISP extra... mdsmedia   | 08/23/06
the cost should fall on the culprit - the dumb user who has the bot. Castanet   | 08/23/06
Would you still boil water before drinking? vmtnezgil@...   | 08/24/06
Do people still use windows IceTheNet@...   | 08/23/06
As much as MS monopoly causes issues davidnewman7798@...   | 08/23/06
Lame kielork   | 08/23/06
Why is it Lame? isawyoo1st@...   | 08/23/06
um kielork   | 08/23/06
um steveh99   | 08/23/06
UMM & then.... oldradiojock   | 08/23/06
You not having a problem rpmyers1   | 08/23/06
you've been hacked will.be.deleted@...   | 08/23/06
Misleading ZDNet stories bernie157   | 08/23/06
Worm is sparked by greed & vandals oldradiojock   | 08/23/06
Wrong focus, folks qhris@...   | 08/23/06
Best OS? As compared to what? oldradiojock   | 08/23/06
I've never bashed MS... mdsmedia   | 08/23/06
MS software is what it is Boot_Agnostic   | 08/24/06
The only reason Microsoft is trying at all slim-01   | 08/24/06

What do you think?

advertisement
advertisement

Ultraportables

advertisement
Click Here