Windows ‘Storm Worm’ rages across globe; Apple Macintosh unaffected

A significant network attack was launched globally in the early hours of Thursday morning (GMT) using news of a European storm as the hook to lure the unsuspecting. The message, which was created and launched literally as the storm raged, is exploiting a timely widescale media event as the key mechanism for delivering its payload.

The Trojan was distributed in messages with subject line of “230 dead as storm batters Europe”. The payload in this case was the Small.DAM Trojan that was downloaded into all vulnerable machines upon opening of the spam mail’s attachment such as “Read More.exe”. Once inside the machine, the Trojan creates a backdoor that can be exploited later by the malware authors behind the assault.

As has been seen with other attacks, the likely intention is to create a new raft of zombie computers to steal information and to further propagate large-scale spam and phishing runs.

In addition to the headline “230 dead as storm batters Europe” the spam uses a number of other provocative headlines. Attachments may be of the following filenames: “Full Clip.exe”; “Full Story.exe”; “Read More.exe” and “Video.exe”.

The assault was first picked up by F-Secure Security Labs Kuala Lumpur during the very early hours of Friday European time. The timing of the assault and its detection in Asia leads researchers to believe that the assault also originated in the region.

User of Apple’s Macintosh computers are unaffected.

  1. Could someone explain to me how it comes Windows users are such IDIOTS? If the attachment has filename with extension .exe what the averaged moron on Windows think it will do by double-clicking it? reading a text file?

    The vast majority of idiots in the world all choose Windows as the OS to run on their computer. They should stick to pen and paper.

    Gotcha: they will still catch and spread virus licking the envelopes. Truth is, you can’t help morons.

  2. As we’ve learned all to well, this TOO won’t matter to tried and true PeeCee users. It’s the Munchausen Syndrome for these idiots or nothing. The more pain and suffering they and their friends have to bear, the more pity and attention they receive.

    As well as . . .


  3. Vista’s idea of security is asking the user for permission to install software (not having to type in a password, just clicking OK). If a user is dumb enough to double click an EXE file they are clearly going to give permission!!!

  4. It’s scary that so many computers vital to the infrastructure of the U.S. run on Winblows. I can’t understand why some person or business or government agency hasn’t sued Mafia$oft for their shoddy OS and the time and money spent shoring it up on the user’s end. Lemmings!

  5. “Could someone explain to me how it comes Windows users are such IDIOTS? If the attachment has filename with extension .exe what the averaged moron on Windows think it will do by double-clicking it? reading a text file?”

    Well, a couple of reasons.

    First, as I understand it, Windows either shows you extensions or doesn’t show you extensions. Unlike Mac OS X, where it is based on the file. So it’s quite possible that Windows is not showing you the extension, because you told it not to. After all, who wants to see all those “.exe”s after the filename.

    Second, most people don’t know to look at extensions anyway and just double-click on the pretty icon anyway. Trust me, Mac users are just as stupid–perhaps more so, because we’re safe from these things.

    “The worm affects Vista installations as well.”

    Well, since it’s delivered as a Trojan, I would have no doubts of it’s ability to infect Vista. The question is, when it tries to install it’s payload, does Vista put up appropriate dialogs asking the user if this is OK.

  6. Quote: “Anyone notice that the ‘Month of Apple Bugs’ has gone fairly silent?”

    No, but what I have noticed is that many of the bugs seem to be X86 based rather than PPC. Also not all are bugs in OSX, but in apps which can lead to a security risk.

  7. “Too Amazing” is right. It’s scary and true: Most Mac users whose computers I have repaired over the past several years would also click on a malware attachment quite happily without a second thought.

    The people that read forums like MDN, MacInTouch, and others may be the “savvy” ones, but we are definately in the minority.

    It’s simply amazing to me that we haven’t seen lots of malware on Macs, even under System 7, OS 8, 9, and so on, based on “social engineering” like the trojan mentioned in the article. Just go to any minute of any day and you’ll see what kinds of forums those guys have going.

