Sober worm lures football fans with 'free tickets'

worm.jpg

The virus then harvests email addresses from the victim and directs a barrage of spam to those addresses. However, the worm avoids sending messages to companies involved in the antivirus and security industry.

Antivirus firm Trend Micro has highlighted the worm's use of social engineering to spread and rated it a "medium risk".

"This is a prime example of social engineering - these games are very popular worldwide and even users who are savvy enough to suspect this email is a fake, may take a risk and click on the attachment anyway in the hopes of getting free tickets," said Jamz Yaneza, senior virus researcher at TrendLabs.

Email security specialist MX Logic has issued a statement warning that Sober is exploiting the fact that FIFA has kicked off the second phase of 2006 ticket sales to the cup on Monday - the same day the variant was discovered.

"This is the latest in a very prolific family of mass-mailing worms… It demonstrates, once again, that worm authors are continually improving social engineering tactics, highlighting the need for businesses and consumers to remain constantly vigilant against the ever changing tactics of worm authors," said Scott Chasin, chief technology officer at MX Logic.

Antivirus firm McAfee has given the worm a "medium" risk rating for home PC users. Craig Schmugar, virus research manager for McAfee Avert, said the multi-lingual abilities of the worm are helping it spread.

"The social engineering has been very effective… They will use German messages for German Windows users. They tell them they've won tickets to the World Cup, and that has been an effective [ploy] for that region," said Schmugar.

Source
 
Back
Top