MX Logic
Resources Support Contact MX Logic Login
Search
MX Logic Advantage Services Technology Partners News & Events About MX Logic

MX Logic » MX Logic IT Security Blog

10 April 2007

Another Storm Worm Variant Hits on Easter Sunday

This past Easter Sunday another variant of what is commonly known as the "Storm Worm" (originally discovered in mid January, 2007) started circulating around the Internet. This worm originally got its name because one of its original iterations used a subject line related to a large storm that was hitting Europe at the time; a certainly not unheard of, yet an effective social engineering tactic.

This new variant appears to be attempting to play on social tensions between the United States and Iran with regards to Iran's developing nuclear weapons program sending itself using email subject lines like "USA Just Have Started World War III", "Missle Strike: The USA kills more then 20000 Iranian citizens", and "USA Missile Strike: Iran War just have started." The email contains a binary executable attachment with fairly innocuous names like "video.exe", "click me.exe", and "readme.exe."

As with the original Storm Worm this new variant spread quickly as unwary users happily clicked the file attached to the message. We haven't seen traffic with this most recent outbreak nearly to the levels that we saw with the original. That is likely because the social engineering tactic used with this latest variant was not nearly as well executed (i.e. it poorly played upon a current news story). Additionally, it was released on Easter Sunday when many folks across the world are celebrating the holiday with their families, and not necessarily checking their email.

Expect to see more variants of this latest malware come out as news stories continue to unfold over the coming weeks. The proof of concept utilizing current events as an initial lure continues to be effective. Outbreak levels, however are not nearly what we have seen in the past with some of the Sober variants from 2005 where emails promising free World Cup tickets and videos of Paris Hilton ran rampant across the Internet. By sheer volume those Sober outbreaks dwarf what we have seen since. Combine overall low user confidence and trust in email with the fact that many malware authors have moved onto more stealth methods of injecting malware onto user's PCs, we are not likely to see email virus outbreaks of that magnitude ever again.

Posted by smasiello at 11:25 AM | Link | 0 comments
MSP Mentor

Privacy Policy
© MX Logic, Inc.
All Rights Reserved.

MX Logic
9781 S. Meridian Blvd. Suite 400 Englewood, CO 80112
Toll-Free: +1.877.MXLOGIC

  MX Logic provides Email Filter, Web Filter and Email Archiving services for use in network security.