Symantec users warned of 'Big Yellow' worm

By Robert McMillan, IDG News Service |  Security Add a new comment

Symantec Corp. customers who have not updated their antivirus software are being targeted by a self-propegating worm, the company said Friday.

The worm, dubbed "Big Yellow," by security vendor eEye Digital Security Inc. has been seen in a handful of attacks, and is not considered to be a serious threat to most users, security vendors say.

The worm exploits a flaw in Symantec's Client Security and AntiVirus Corporate Edition software, which was patched last May, so only out-of-date versions of the product are at risk.

The company's Norton products are not affected by the flaw.

Symantec first noticed some scanning activity on the Internet related to this attack, on Wednesday, said Vincent Weafer, senior director with Symantec Security Response. "Since then it's gone to a background level," he said. "We have had three submissions locally from our customers."

The worm looks on port 2967 for unpatched clients. When it finds them, it installs its malicious software on the user's system, Weafer said.

A separate attack, which also exploited the same flaw, surfaced in late November, Weafer added. In that case, attackers focused on about a dozen educational institutions.

"It occurred over a two-day period and then died down. This time around, with this new bot worm, we're not even seeing that [level of] activity."

Though eEye put out a news release Friday warning of the worm, the malware has not caused much concern in the security community because it is not widespread, said Russ Cooper, a senior information security analyst at Cybertrust Inc. "This is [eEye] drumming up year-end press," he said.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question