New Sober variant tricking users
IDG News Service - A new Sober mass-mailer worm is slithering its way around the Internet and tricking users into opening attachments with clever messages in both English and German, antivirus companies warned.
W32.Sober.N@mm sends e-mail messages with the subject headers "I've_got your EMail on my_account!" and "FwD: Ich bin's nochmal" and carries attachments with names like your_text.zip, according to Helsinki security firm F-Secure Corp. When opened, the attachment scans files on the infected computer to harvest e-mail addresses that enable the worm to spread.
Symantec Corp. also released an advisory on the Sober variant, rating its damage as "medium."
The worm was first reported at 2 a.m. CET, and has been spreading in Europe, particularly in German speaking countries, according to Mikko Hypponen, director of antivirus research at F-Secure.
The body text for the English version begins "Hello, First, Very Sorry for my bad English. Someone is sending your private e-mails on my address." It then tells the recipient that 10 of their personal e-mails are attached in a zip file.
The message represents a clever bit of social engineering because it appears plausible, and in the case of the German versions, is in a local language, Hypponen said. Most users are accustomed to receiving spam and viruses in English, he added.
The motive behind creating the worm is still unclear and F-Secure does not know the identity of the author, Hypponen said.
It's difficult to tell how rapidly the worm is spreading because the author used computers infected with a previous version of Sober to launch the new variant and "get a head start," Hypponen said.
The researcher said the author is based in Europe because Sober variants are always released early in the morning European time, giving them a chance to spread before the antivirus companies start their day.
F-Secure and Symantec both advised Internet users to update their antivirus software to guard against the new worm.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts