Virus Alert
Virus Alert

New worm masquerades as Microsoft update

Sober variant employs latest social engineering technique

Written by Iain Thomson

A new variant of the Sober worm has surfaced this morning, antivirus specialist F-Secure has warned.

Sober D pretends to be a Microsoft software update that protects against a new version of the MyDoom worm.

Once activated the worm displays a patch loading screen, but harvests email addresses and mails itself out using its own SMTP engine.

The email, written in either English or German, has the headline 'Microsoft alert: please read!' The body text adds: 'New MyDoom virus variant detected - please download this digitally signed attachment.'

Paul Bushen, technical manager at F-Secure UK, told vnunet.com: "The social engineering is good enough to do the job of fooling people.

"People are not learning quickly that Microsoft does not send out emails like this.

"It's like remembering to back up your hard drive regularly: something that's done religiously, but only by those who've been caught out in the past."

Sober A first surfaced in October 2003, again using either English or German text and a variety of social engineering techniques.

The virus has previously been disguised as a Microsoft email and as one from the Recording Industry Association of America.

Tags:

Further reading

Sober variant set to cause trouble

Heightened risk assessment for Sober.f strain spotted in the wild   More...

Network Box of tricks to target viruses

Supplier seeks resellers for remotely managed hardware aimed at SMEs   More...

Virus war of words falls silent

Netsky and Bagel variants continue to spring up, but virus writers' slanging match cools down   More...

Worms still number one security threat

MyDoom.A and Sober C lead the pack, Bagel and Netsky catching up fast   More...

Related articles

Virus and phishing attacks soar in September

Second surge of email attacks targeted at executives   More...

Storm malware still blowing strong

One year on and no sign of fading away   More...

Storm resurfaces for Valentine's Day

Old worm, old trick   More...

'Malware 2.0' raises its ugly head

Signature-based security unable to cope with 'zero-minute' threats   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement