“Windows users are being warned about a virus that is ‘aggressively stealing’ credit card numbers and passwords,” BBC News reports. “The Korgo virus debuted on 22 May and since then has been steadily racking up victims.”
“Although the virus is not widespread, security firms are issuing warnings because it is proving so effective at stealing confidential data,” BBC News reports. “Those infected by Korgo are being urged to change passwords and credit cards if they have been used online recently… the Korgo worm spreads around the net by itself… ‘This is quite an effective one,’ said Mikael Albrecht, product manager at F-Secure. ‘There’s a real danger that your online banking ID would get into the wrong hands,’ he said.”
Full article here.
MacDailyNews Take: Ahh, the joys of running a Windows PC. Is a Windows PC really less expensive than an Apple Macintosh? More info about smoothly adding a Mac to your computing arsenal here.
Another day, another virus.
Lather, rinse, repeat.
Let’s review the steps…
Step 1. Buy cheap PC at Walmart for $495
Step 2. Spend 10 hours getting the thing to work so you can buy stuff online. (if your time is worth something the setup costs you $59 in labor – Walmart PC buyers make at least minimum wage
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
Step 3. Get infected by Korgo
Step 4. A hacker steals your credit card number.
Step 5. Notice a month later (when your credit card statement arrives) that a 42″ Plasma Screen was purchased with your card: $6000.
Step 6. You look in your living room and verify that you still have your 26″ Samsung TV and not a new 42″ Plasma HDTV.
Step 7. You realize that your new Walmart PC actually cost you $6554.
FUD from MDN…
This is not a virus this is a program that users had installed on their machine…
Just like the current state of OS 10.x.x just visit a site and a program is installed on your HD with out your permission…
Whats the big deal this is life on the internet in the year 2004. All users should think about creating a separate user for surfing. And remember that every little shareware app could be a wolf in sheep’s clothing.
SP2 for XP is going to alert a user when a application is installed with out the users permission. At least MS cares about providing solutions to problems. And the soon to be released Longhorn will create a ultra-safe modern computer environment.
�
Notice how the BBC have started saying “Windows users are being warned…”
I wrote an email complaining that they never specified which machines were vulnerable. They must have listened to me. At least I hope they did.
“Soon to be released Longhorn”?!?!?!?!? What is so soon about 2008??!?!?!!?!
Sputnick,
It’s always “when” with you. Try talking about “now” and get your head out of the clouds.
I can’t wait to see what M$ have to say about this. Maybe they’ll introduce a new category of update – “Extremely Absoulutely Critical Update”
Last month Windows got 1000 new virus.
That is about 31 every day!
31! Every single day that makes over 11 000 viruses every year.
Now there is more than 90 000 windows virus going around.
Sputnick,
“FUD from MDN…”
MDN are quoting the BBC, the largest news organisation in the world (quite possibly). I don’t think it’s FUD when it comes from them.
twelveightyone, you need to make a correction. Sputnik’s head is not in the clouds. It’s up his ass!
Windoze Users: If you’re not sure if you’ve been infected, according to F-Secure, you should — “Change your passwords and cancel your credit cards. Especially the ones you’ve used during last week.”
[Then get out of Windows and go buy a Mac while you can. If you’ve been infected and find yourself somewhat poorer, you may never have that option again.]
“This is not a joke.” [Then why am I (cough) laughing?]
All kidding aside, this is getting scary.
Jimbo von Winskinheimer,
Sorry, I stand corrected
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
His head IS up his ass!
Sputnik,
I’m not sure what makes you think this is a Trojan. The advisory clearly states:
“W32.Korgo.C is a worm that propagates by exploiting the LSASS vulnerability on TCP port 445 (as described in Microsoft Security Bulletin MS04-011) and opens a backdoor on TCP ports 113 and 3067.
This worm is a backdoor threat. A Trojan, by definition, comes in through the FRONT door.
Feel free to diminish the danger of this kind of worm. The more Windows users who get compromised, the more switchers to Macintosh there will be.
Already, on our university campus, we are warning all of our purchasing card Windows users who have recently used their university purchasing card, to cancel them. We are even considering whether Windows users should use such cards online in the future. It would not surprise me if the campus limits online credit card purchasing to Mac users only.
-B
Actually this is much more of a problem for the credit card companies than for the end users. You don’t have to pay for purchases you don’t make. I know because somebody hacked a DB and got my credit card number and used it but I didn’t have to pay for any of it.
Unfortunately the credit card companies DO have to pay I believe; so the end users get it in the end anyway by having the costs passed down. When are people going to wake up? Swiss Cheese windows costs everybody money. Even us Mac Users indirectly. 🙁 I think M$ should have to give some of their cash hoard back.
Less Is More – LOL!
“Actually this is much more of a problem for the credit card companies…”
Well, here’s the thing with corporate purchasing cards. While one can still contest a fraudulent charge, there is a LOT more paperwork to deal with doing so. Large institutions like universities have very specific protocols for dealing with incorrect or fraudulent charges and many hoops have to be jumped through (including contacting the vendor first), before the bank is involved.
In short, it’s a bookkeeping nightmare.
-B
every program installed on a mac, needs permission and a password, first! If in some service pack, windows tells you after something is installed = how much use is that? Active X controls dont work on a mac, and they can do hella damage to a pc, and so on and so on…
I do have a serious question for any knowlegable Win users reading this thread.
If you patched for Sasser are you safe from Korgo variants?
-B
Wouldn’t it be funny if someone wrote a Windows worm that placed a Mac order at the Apple Store on the credit card, and had them delivered to the owners address?
How many would take the hint and keep it?
Dave H, that is brilliant! I love it.
Dave H wrote:
“Wouldn’t it be funny if someone wrote a Windows worm that placed a Mac order at the Apple Store on the credit card, and had them delivered to the owners address?”
I would hate to see you go to jail Dave for trying this but yes, it would be funny
” width=”19″ height=”19″ alt=”grin” style=”border:0;” />
-B
I’m a fag with attitude. Hug me!
Jimbo: Not without upsetting Jay or Ron, the voices of tolerance and reason.
Dave H: Wizard wheeze!
Jimbo/1281: You’re both wrong – his head IS his ass.
All this talk about “worms” and “Trojans” is making me horny.
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
Sputnik: “This is not a virus, it is a program that users had installed”
Can someone explain how comes Windows users who should be the leading experts on viruses, worms, trojans, etc. are the most clueless not being capable of telling orangel from apples?
LOL Sputnik, I guess you proved Microsoft is kinda right when they say their major problem with security comes from their widely ignorant users base.
I realize it is not MS PR, it is really Windows users are blockheads.
“”W32.Korgo.C is a worm that propagates by exploiting the LSASS vulnerability on TCP port 445 (as described in Microsoft Security Bulletin MS04-011) and opens a backdoor on TCP ports 113 and 3067”
Well, in a sense Sputnik is also right: viruses and worms are to Windows just like all other programs that users had installed on their PC: Gartner estimates an average of 29 of these *programs* installed on the average PC. No need to surf: self propagating, just like Korgo.
BTW, Korgo exploits the same flaw as Sasser. Was not everybody told that the hole was filled? LIARS.
Enjoy your vastly larger selection of *programs* installed on PCs.
“worms”??? Speak for yourself. We’re talking ANACONDA here.
Beeblebrox, I can’t answer your question directly, but I did notice on Symantec’s site that Korgo only infects Windows 2000 and XP, which, as we all know, are the most secure versions of windows available. I actually only checked Korgo versions E through G, so I could be wrong about any/all of the A through D versions of Korgo. Isn’t it amazing that it takes so long for m$ to come out with a new version of windoze; it takes less than a day for someone to come out with a new version of windoze viruses!
When this issue came up in our organization this morning (we have 3000 employees, half use Windows half use Macs), the security people were asked whether Windows users should stop using their credit cards on line. You might be interested in their responses:
“If you are serious with your question, you should not limit the
restriction to Windows. Keyloggers can be installed on any OS.”
“First off, using a credit card online will have some level of risk. In fact, using a credit card at a physical location (i.e., not online) will also have a degree of risk (e.g., a gas station attendant who copies down credit card numbers).”
“Do we only worry about systems that can have keyloggers installed via
worms? Root compromises are a great delivery path for keyloggers.”
Even though these three comments were from the security staff at our organization, it probably would not surprise you to know that all three are Windows users.
Hehe Backdoor…
So what does the F in F-Secure stand for?
Hey Sputnick, Just curious why you never defend yourself or provide back up information to refute the data others have refuted your comments with? No confidence or trust in your statements/opinions?
did anyone else get spoof mail in the last 48 hours?
So what does the F in F-Secure stand for?
Finland?
did anyone else get spoof mail in the last 48 hours?
Yeah, a bogus eBay message with a link to some geocities page.
ANACONDA???
We’re talking DUNE WORM here! Pucker up, W_users.
Uh, sorry. I am Moron.
Regarding the quotes posted by “Don’t trust security experts”, it is my experience that most “security experts” are Windows centric and make their money off of Windows security threats. Thus, the three quotes don’t surprise me at all. The quotes have, as their underlying motivation, a desire to deceive people into thinking that all platforms are equal and that security attacks can hit anyone.
The true reality is that if people were to start migrating to OS X in droves, many “security experts” would be out of a job.
-B
Cheap Walmart PC: $400
10 hours to install: $59
Having all your credit card numbers and bank passwords stolen by the Korgo worm: Priceless
We ought to make a poster.
About F-Secure.
I really don�t know what the name stands for. F possibly means Finland.
IMNHO it is the worst name ever invented.
Then again the company itself is great. They should change the name ASAP.
LOL John, I suppose you are talking minimum wage there. If that was the case the chap would be right to go for a $400 but would probably have no access to a credit card, at most a debit one.
The sad real scenario is with people being able to afford a real computer running a serious OS and instead stick with a overpriced game console running some sort of Windows. So it would be:
10 hours to install: $890
It is not the credit card companies who end up eating fraudulent charges, it is the merchant who accepts the credit card. When a credit card user refutes a charge, the credit card companies go back to the merchant who made the charge. If the merchant can’t prove that the customer made the charge, such as having a customer signature, the credit card company takes the funds from the merchant’s account. On top of that, credit card companies often assess fees from merchants for accepting a fraudulent charges.