It will go down in the security industry’s chronicles as the “Here You have” virus. That’s the subject line of an e-mail carrying a worm that wreaked havoc on corporate America on Thursday.
The e-mail offered a link to documents the malware author hoped recipients would click on. But the URL doesn’t lead to a document or a movie — it downloads a worm on to the victim’s computer.
Disney, NASA, Proctor & Gamble, AIG, the Florida Department of Transportation and Wells Fargo are among the companies hit with the worm. Once the victim is infected, the worm attempts to send the same malicious message to the victim’s e-mail address book recipients. It can also spread through instant messenger.
Graham Cluley, a senior security analyst at Sophos, called the virus a “real throw-back to the viruses of yesteryear.” “These days we normally see stealthy Trojan horses so to see such a high profile e-mail worm is a real novelty,” Cluley said. “It can also spread via network shares.”
The virus is spreading rapidly, but how dangerous is it? According to Cluley, the intention of the attack appears to be to steal information.
“The malware downloads components and other tools which extract passwords from browsers — Firefox, Chrome, Internet Explorer, Opera — various e-mail clients, and other applications,” he said. “Clearly, sensitive information which you don’t want falling into the wrong hands.”
At the moment, the virus appears to have run out of steam. Cluley said the links aren’t currently pointing to malware, although there may still be e-mails being sent from already infected computers. The question is, why weren’t companies prepared for the attack? Cluley said some were.
“Some firms were running proactive defenses which identified the e-mails as being spam, or the malware at the links as being dangerous,” Cluley…