| By Linux News Desk | Article Rating: |
|
| January 30, 2004 12:00 AM EST | Reads: |
18,885 |
Rampant E-Mail Virus Traced to Russia
Friday, Jan. 30, 2004By Simon Ostrovsky Staff Writer
"MyDoom, the fastest-proliferating computer virus ever, has been traced to Russia.
Using location-sensing software, Kaspersky Labs has traced the first e-mails infected with MyDoom back to addresses with Russian Internet providers.
"It's scary, but most serious viruses are written in Russia," said Denis Zenkov, spokesman for Kaspersky, the country's largest anti-virus software company.
Ever since it first appeared Monday night, the virus has managed to latch onto every 12th e-mail sent, slowing down Internet traffic around the world.
"This virus can only be compared to chemical warfare, an indiscriminate weapon of mass destruction," said Mikhail Yakushev, a legal adviser for Microsoft in Russia.
MyDoom breaks a previous record set by the Sobig worm, which infected one in every 21 messages at its peak last summer.
Most disturbing is that the virus gives its creators -- or anyone who cracks the virus's code -- the power to take control of an infected PC.
The virus has already infected 600,000 to 700,000 computers around the globe, Kaspersky Labs estimates.
And it has caused some $2 billion in losses worldwide, according to Computer Economics, an Internet monitoring company.
Thirteen percent of infected computers are in the United States, compared to a figure of under 1 percent for Russia, according to Kaspersky Labs.
"Russia usually does better fighting e-mail viruses than the United States because systems administrators are generally more competent here and install protection quicker," Zenkov said.
Russia might be better prepared, but then it is often the source of server-stomping viruses, as in the case of MyDoom.
"We don't understand why, because usually programmers write viruses during an economic downturn when there is no work and nothing else to do," Zenkov said. "Right now there is plenty of work for Russian programmers."
The cause of damage is not primarily the virus's ability to take control of an infected computer and change information stored on the hard drive.
Instead, the virus wreaks havoc by sending itself to all the addresses stored inside an infected PC, exponentially increasing e-mail traffic and overloading web servers.
MyDoom spreads as an attachment to e-mails or as a file on the KaZaA file sharing system. It uses a multitude of file names, subject lines and file extensions, making it difficult to notice.
When the infected attachment is opened, the virus automatically installs files in the computer's system, making it possible to use the computer as a proxy server for sending out future versions of the file and to take control of the computer itself.
"If the virus's creators don't send out an updated version of the virus it will be under control in the next few days," Zenkov said.
MyDoom is not the only virus traced to Russia. Dumaru and Mimail have also betrayed Russian origins.
But MyDoom has been the most problematic. One Utah-based software company, SCO, has gone so far as to offer $250,000 for any information leading to the arrest of the virus programmers.
SCO's web address is specifically targeted by MyDoom. The virus is encoded to bombard SCO's web site with requests every 50 milliseconds starting Feb. 1. Such a huge volume of requests is almost certain to crash the company's server, causing huge financial losses.
SCO has branded MyDoom as "criminal activity that must be stopped." In a statement on the company's web site, president and CEO Darl McBride said "we have our suspicions" as to the perpetrators. He did not elaborate.
SCO is one of the most ardent opponents of the open source code movement, which calls for software companies to make their programming code available to the public.
If convicted of creating or distributing harmful computer programs, hackers face up to seven years imprisonment under Russian law, according to Microsoft's Yakushev. The Federal Security Service said it was not able to confirm immediately if a criminal investigation had been opened into the MyDoom case.
If it has, the FSB shouldn't look for some teen computer whiz. "Its creators are skilled professionals," Zenkov said."
Published January 30, 2004 Reads 18,885
Copyright © 2004 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Linux News Desk
SYS-CON's Linux News Desk gathers stories, analysis, and information from around the Linux world and synthesizes them into an easy to digest format for IT/IS managers and other business decision-makers.
- Microsoft Tries Hadoop on Azure
- Asynchronous Logging Using Spring
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- AT&T Joins OpenStack, Floats Cloud Architect
- Red Hat Sets Up GlusterFS Advisory Board
- Linux Virtualization and Tired Open Source Myths
- OpenOffice.com Lives
- Cloud Computing: A Platform-First Approach
- Powering the Cloud with Open Source
- Acquia Announces Two New Board Members
- Adobe Sends Flex to the Apache Foundation
- i-Technology in 2012: Five Industry Predictions
- Microsoft Tries Hadoop on Azure
- OpenXava 4.3: Rapid Java Web Development
- Asynchronous Logging Using Spring
- StorSimple Supports OpenStack
- What to Expect in 2012: Cloud Computing and Open Source Software
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- AT&T Joins OpenStack, Floats Cloud Architect
- More Use Cases for Big Data Analytics
- Red Hat Sets Up GlusterFS Advisory Board
- Linux Virtualization and Tired Open Source Myths
- After Ubuntu, Windows Looks Increasingly Bad, Increasingly Archaic, Increasingly Unfriendly
- SCO CEO Posts Open Letter to the Open Source Community
- Simula Labs Launches Hosted Delivery Platform To Enable Enterprise Open Source Adoption
- Where Are RIA Technologies Headed in 2008?
- Source Claims SCO Will Sue Google
- How Open Is "Open"? – Industry Luminaries Join the Debate
- Latest SCO News is Plain Weird
- SCO Claims Linux Lifted ELF
- IBM Tells SCO Court It Can't Find AIX-on-Power Code
- Flashback: Investing in 'Professional Open Source' - Exclusive 2004 Interview with David Skok, Matrix Partners
- Developing an Application Using the Eclipse BIRT Report Engine API
- HP Starts Pushing Desktop Linux























