New Sober variant tricking users
IDG News Service -
A new Sober mass-mailer worm is slithering its way around the Internet and tricking users into opening attachments with clever messages in both English and German, antivirus companies warned.
W32.Sober.N@mm sends e-mail messages with the subject headers "I've_got your EMail on my_account!" and "FwD: Ich bin's nochmal" and carries attachments with names like your_text.zip, according to Helsinki security firm F-Secure Corp. When opened, the attachment scans files on the infected computer to harvest e-mail addresses that enable the worm to spread.
Symantec Corp. also released an advisory on the Sober variant, rating its damage as "medium."
The worm was first reported at 2 a.m. CET, and has been spreading in Europe, particularly in German speaking countries, according to Mikko Hypponen, director of antivirus research at F-Secure.
The body text for the English version begins "Hello, First, Very Sorry for my bad English. Someone is sending your private e-mails on my address." It then tells the recipient that 10 of their personal e-mails are attached in a zip file.
The message represents a clever bit of social engineering because it appears plausible, and in the case of the German versions, is in a local language, Hypponen said. Most users are accustomed to receiving spam and viruses in English, he added.
The motive behind creating the worm is still unclear and F-Secure does not know the identity of the author, Hypponen said.
It's difficult to tell how rapidly the worm is spreading because the author used computers infected with a previous version of Sober to launch the new variant and "get a head start," Hypponen said.
The researcher said the author is based in Europe because Sober variants are always released early in the morning European time, giving them a chance to spread before the antivirus companies start their day.
F-Secure and Symantec both advised Internet users to update their antivirus software to guard against the new worm.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Key Strategies for Managing Data Growth
What are you storage challenges?
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
