On CBS.com: Watch Exclusive CSI Cross Over Video
BNET Business Network:
BNET
TechRepublic
ZDNet

By Alorie Gilbert
Posted on ZDNet News: Oct 26, 2005 7:33:00 PM

Fewer businesses fell victim to the Zotob worm that struck corporate networks than previous attacks, but those it hit paid dearly, according to a new survey.

The August worm caused disruptions for about 13 percent of the organizations surveyed by computer security firm Cybertrust, which released the results of a 700-company study Wednesday. As reported earlier, Zotob's victims included cable news station CNN, TV network ABC, The New York Times and DaimlerChrysler.

Six percent of survey respondents said Zotob's impact on their company was moderate to major, which was defined as more than $10,000 in losses and at least one major business system affected, such as e-mail or Internet connectivity.

Alarming as it was, Zotob did far less damage than did other major worms designed to exploit Windows vulnerabilities, Cybertrust said. For example, the Nimda worm made a moderate to major impact on 60 percent of companies. MSBlast (aka Blaster) struck about 30 percent of organizations to that degree, the firm said.

Zotob was less widespread, in part, because it targeted only PCs running Windows 2000, an older version of the software. The worm exploited a hole in the operating system's plug-and-play feature, and let attackers take control of infected machines while spying on users.

Most businesses became infected through vulnerable computers wired to the corporate network, rather than wireless pathways or e-mail, Cybertrust said. A full 26 percent of Zotob victims told the firm that infections occurred because they had no firewall in place.

The average cost of recovering from a Zotob infection was $97,000, Cybertrust said. For 61 percent of victims, cleanup required more than 80 hours of work. The health care industry was hit hardest, with more than a quarter of that sector's organizations reporting some impact, according to the survey.

But the more limited scope of the attack is not necessarily an encouraging sign, Cybertrust said. Rather than indicating that businesses are wising up to vulnerabilities, the survey shows that hackers' goals are changing.

"The nature of this worm and its ultimate business impact complements Cybertrust's intelligence that illustrates the goal of hackers today is no longer widespread system shutdown, but rather more frequent, smaller attacks with specific targets powered by a drive for financial and information gain," Russ Cooper, Cybertrust analyst and the study's author, said in a statement.

Indeed, two men arrested in Turkey for allegedly unleashing Zotob and other worms are thought to be part of a credit card fraud ring.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 10 Talkback(s)
Zotob damage deep but not widespread
... (Read the rest)
Posted by: bryanpeabody Posted on: 02/22/06 You are currently: a Guest | | Terms of Use
malicious payloads vs. remote controlled botnets  nynetsec | 10/26/05
I won't consider them a fool but...  Grayson Peddie | 10/26/05
These numbers are BS  toadlife | 10/26/05
Maybe not...  gfeier | 10/27/05
Understanding survey results  NTBugtraq | 10/27/05
Hello Russ  toadlife | 10/27/05
correction  toadlife | 10/27/05
correction  toadlife | 10/27/05
A beautiful piece if coding!  An_Axe_to_Grind | 10/27/05
Zotob damage deep but not widespread  bryanpeabody | 02/22/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and