On mySimon: North Face Elkhorn 0 Degree Sleeping Bag
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 28, 2005 8:01:00 PM

A new version of the Bagle virus is attempting to turn PCs into zombies for use in cyberattack networks.

The variant surfaced over the weekend and was spammed to tens of thousands of Internet users, Ero Carrera, a researcher at F-Secure, said Tuesday. The antivirus software maker is calling the offshoot Mitglieder.CN, but it is known by other names, such as Bagle.BQ or Tooso.J, at other security companies.

The latest Bagle behaves in a similar way to its predecessors that don't self-propagate. It arrives in an e-mail with a attachment. When the file is executed, the malicious program tries to disable firewalls and antivirus software. It then attempts to download and run a Trojan horse that hijacks the infected PC for use as part of a botnet.

Botnets are groups of compromised PCs, often numbering in the thousands per network, that are rented out to relay spam, to launch denial-of-service attacks, or to perform other malicious acts.

"Compromised PCs could be used to send out new variants of Bagle," for example, Carrera said.

Bagle has spawned at least 70 variants since the virus emerged in January 2004. Some iterations have been more sophisticated than others, blending mass-mailing and Trojan horse techniques.

Most antivirus companies updated their products over the weekend to protect customers against the new virus. "It is not going to be a major issue," Mikko Hypponen, director of research at F-Secure, said Monday.

Symantec rates the new variant a low risk because it has not spread much. "Our rate of submissions is slowing down on that variant, so we don't consider it to be a significant threat," a Symantec representative said Monday.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 15 Talkback(s)
No, opening e-mail is NOT the ONLY way, BUT...
...it IS the MOST prevelant way with these new infected JPEGs moving up fast to second place.

In addition to which, what about the one pixel web beacon? THAT thing is spyware..... couldn't that... (Read the rest)
Posted by: btljooz Posted on: 07/16/05 You are currently: a Guest | | Terms of Use
Time to grow a brain or disconnect that PC, folks!  rick752 | 06/28/05
Since you seem to be above everyone else...  DarbyOhara | 06/29/05
AVG Free 7.0  bammike | 06/29/05
AVG Free 7.0  bammike | 06/29/05
Hmmm .. a double post with a pitch ....  rick752 | 06/29/05
You never had that happen to you? You just  btljooz | 07/16/05
I'm not above anyone else  rick752 | 06/29/05
He's got a point  voska | 06/29/05
Thanx, but unfortunately....  rick752 | 06/29/05
Other major cause is English  meinhardt_jg | 06/30/05
No, opening e-mail is NOT the ONLY way, BUT...  btljooz | 07/16/05
It's called Deliberate Stupidity  btljooz | 07/16/05
All your computers are belong to us  Squawkbox | 06/29/05
lol  linuxoverwindows | 06/30/05
Yeh, RIGHT....  btljooz | 07/16/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads