The eight -- dubbed Mytob.j through Mytob.s with some final letter designations skipped -- are mass-mailed worms that spread by sending themselves to addresses they find on the target Windows PC. They can also spread, said Symantec, by exploiting the LSASS vulnerability in Windows. That bug, first disclosed in an April 2004 security bulletin, http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx has been patched by Microsoft. Still, it remains a favorite target of hackers, who continue to find unpatched systems.
The worm comes with a variety of subject headings and attached file names and formats, but it often appears with the subjects of "Mail Transaction Failed" and "Error."
All of the Mytob copycats have been labeled with a "2" warning level by Symantec, which uses a 1 through 5 system.
Two new variations -- Mytob.r and Mytob.s -- had appeared by mid-morning Monday, following one on Sunday, three last Friday, and two last Thursday.
Stay connected and informed by visiting our Enterprise IT Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government, Retail and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.