Mass email worm found spreading

Never mind the advanced persistent threat. A new mass-mailing worm that may conjure up images of Nimda and Code Red appears to be threatening email infrastructures.

Using the subject line, "Here you Have," the messages began invading inboxes on Thursday, Craig Schmugar, threat researcher at McAfee Avert Labs, said in a blog post. The emails contain a link that appears to lead to a PDF file but actually directs users to a malicious .SCR executable.

Researchers are unclear of the extent of the outbreak.

If users click on the link, they are prompted to install the worm, which attempts to disable security software and, in the spirit of the worms that crippled businesses nearly a decade ago, send a copy of itself to all email contacts belonging to the victim.

"Once [the computer is] infected, the worm attempts to send the aforementioned message to email address book recipients," Schmugar wrote. "It can also spread through accessible remote machines, mapped drives, and removable media via AutoRun replication."

The link included in the emails studied by McAfee is no longer live as of early evening EST, but researchers warn that multiple variants may be spreading.

McAfee suggests administrators filter out .SCR files from their email systems.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.