Sober worm lures football fans with 'free tickets'

New variant pretends to be FIFA communiqué offering free 2006 World Cup tickets

By Munir Kotadia, 3 May 2005 09:15

NEWS A variant of the Sober virus was discovered on Monday that attempts to fool people into executing its payload by pretending to be an email from football world governing body FIFA offering free tickets to the 2006 World Cup in Germany.

The latest Sober worm, which operates in a similar fashion to others of its kind, uses various email subject headers to try to entice people into opening its attachment. The virus then harvests email addresses from the victim and directs a barrage of spam to those addresses. However, the worm avoids sending messages to companies involved in the antivirus and security industry.

Antivirus firm Trend Micro has highlighted the worm's use of social engineering to spread and rated it a "medium risk".

Jamz Yaneza, senior virus researcher at TrendLabs, said: "This is a prime example of social engineering - these games are very popular worldwide and even users who are savvy enough to suspect this email is a fake, may take a risk and click on the attachment anyway in the hopes of getting free tickets."

Email security specialist MX Logic has issued a statement warning that Sober is exploiting the fact that FIFA has kicked off the second phase of 2006 ticket sales to the cup on Monday - the same day the variant was discovered.

Scott Chasin, chief technology officer at MX Logic, said: "This is the latest in a very prolific family of mass-mailing worms… It demonstrates, once again, that worm authors are continually improving social engineering tactics, highlighting the need for businesses and consumers to remain constantly vigilant against the ever changing tactics of worm authors."

Antivirus firm McAfee has given the worm a "medium" risk rating for home PC users. Craig Schmugar, virus research manager for McAfee Avert, said the multi-lingual abilities of the worm are helping it spread.

"The social engineering has been very effective… They will use German messages for German Windows users. They tell them they've won tickets to the World Cup, and that has been an effective [ploy] for that region," said Schmugar.

Munir Kotadia writes for ZDNet Australia

CNET News.com's Dawn Kawamoto contributed to this report

Comments

There is 1 comment. Join the discussion

  1. 1. anonymous

    Crackers are the number one enmey of US Industries today."OSI" is the critical operation that is used as the basis of the Information brokers.

    After some exploration on their part they build their mission critical door.

    Than they target the people that fit their profile.Once this is done they use this form of Information to intice them with a ghosted E-mail that their target would trust!

    Profileing is the Key Word! Than they open the back door not only to their work but to their family and friends.

    Key words is another method used to gain access to their friends and coworkers life and work profile.

    I tried just to give you a simple example that some deploy in the use of their tradecraft!

    These preditores may just use a form such as yours as a tool?

    Regards.
    Chuck D.,CIO, OCP, CPP

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ