Mytob Mania Won't Stop - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
News
News
6/17/2005
02:36 PM
50%
50%

Mytob Mania Won't Stop

The Mytob worm family keeps popping out newborns, security firms say, with no signs that the variants will stop any time soon.

The Mytob worm family keeps popping out newborns, security firms noted Friday, with no signs that the variants will stop any time soon.

The Mytob worm, which first appeared in late February, is a mass-mailed worm that hijacks addresses from compromised PCs to spread using its own SMTP engine, drops a backdoor Trojan so more malicious code can be added to the infected system, tries to shut down security software already on the computer, and blocks access to a large number of security and update-oriented Web sites.

Security firms such as Symantec have tracked and labeled over 130 different variations on the Mytob worm in the last three-and-a-half months. So many variants have appeared, using so many different techniques -- including phishing-style tactics -- that some analysts believe the group responsible is crafting a "super" worm.

In the last 7 days, Symantec's identified 19 different Mytobs, an average of 2.7 new variants per day, an unheard-of number.

"In the last 24 hours, the Mytob family has accounted for 58 percent of all [virus] reports," the U.K.-based to Sophos said in a statement. Fourteen of the top 20 threats, Sophos added, were Mytob variants.

"There is nothing to suggest that the slew of Mytobs is tailing off," said Carole Theriault, a senior security consultant at Sophos.

Although most Mytob variants propagate via e-mail, some -- including several launched in June -- scan the Net for PCs vulnerable to a variety of Windows vulnerabilities, such as the LSASS bug that Microsoft patched more than a year ago.

One such vulnerability-sniffing Mytobs -- dubbed Mytop.ea by Symantec -- now accounts for fully 15 percent of all malicious code processed by Sophos, said Theriault.

"Patching against operating system vulnerabilities has never been more important. Users want to ensure that their barriers are up and ready to thwart these beasties," she added.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
The State of Cloud Computing - Fall 2020
The State of Cloud Computing - Fall 2020
Download this report to compare how cloud usage and spending patterns have changed in 2020, and how respondents think they'll evolve over the next two years.
News
Top 10 Data and Analytics Trends for 2021
Jessica Davis, Senior Editor, Enterprise Apps,  11/13/2020
Commentary
Where Cloud Spending Might Grow in 2021 and Post-Pandemic
Joao-Pierre S. Ruth, Senior Writer,  11/19/2020
Slideshows
The Ever-Expanding List of C-Level Technology Positions
Cynthia Harvey, Freelance Journalist, InformationWeek,  11/10/2020
Register for InformationWeek Newsletters
Video
Current Issue
Why Chatbots Are So Popular Right Now
In this IT Trend Report, you will learn more about why chatbots are gaining traction within businesses, particularly while a pandemic is impacting the world.
White Papers
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll