New botnet resurrects Storm's Valentine's Day ruse
Spam trumpeting the power of love is nothing more than an old trick dressed up in new clothes, more evidence that the backers of the Waledec bot Trojan are the same bunch that hammered users last year with Storm, security companies are warning.
Multiple security vendors, including MX Logic Inc. , Trend Micro Inc. and Panda Security, have issued alerts about new Valentine's Day-themed spam campaigns that try to dupe users into installing the Waledec bot.
Subject lines for the spam, said Sam Masiello , vice president of information security at MX Logic, are "short and sweet," and include "Me and You," "In Your Arms" and "With all my love." From the spam, users who browse to the embedded link reach a site with a dozen hearts, any one of which download an executable file when clicked.
Masiello first noted the campaign last Thursday, but other researchers, including those at Trend Micro and Panda, picked up on the trend Monday. Both Masiello and Florabel Baetiong, an anti-spam research engineer with Trend, noted the similarity between the recent infection attempt and Valentine's Day scams launched last year by hackers controlling Storm, another bot Trojan that has since fallen into disuse, possibly because the crew responsible surrendered to heavy pressure by security experts .
"Clearly the old Storm folks are working as hard as they can to build up their new botnet, and are following the old tried-and-true methods of centering their social engineering tactics around holiday themes," said Masiello in a post to the MX Logic blog .
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
spam
Powered by TwitterOn Twitter now
spam
Brian Proffitt
Microsoft/Novell: Breaking Down the Coupon Numbers
Esther Schindler
Drupal's Dries Buytaert on Building the Next Drupal
Tom Henderson
Top Ten General Operating Systems Rants
pasmith
PS3 motion controller delayed; goes up against Project Natal
sjvn
Neolithic Windows security hole alive and well in Windows 7
claird
Perl source code comparison makes for good reading
mikelgan
Cell phones don't create stress or interrupt much
Sandra Henry-Stocker
How to: The Unix Interview
Where Google Chrome security fails: the password
I heard mention that the Chrome OS will have some sort of encryption available a la bitlocker. If it's possible to encrypt personal data using another password or key, then it may have potential for very secure data.... And Ubuntu has an 'encrypt home directory' option, perhaps google should follow suit.
- Dann
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
- Ubuntu advances: Why Ubuntu server installations will surge in 2010
- Social media marketing: How to make friends with benefits
- More...
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.







Clear your computer of all the same bugs.
When you are searching for antispyware there is one that you can always depend on, it’s called Search-and-destroy Antispyware. The antispyware solution from Search-and-destroy can provide you with a scan that can find and clear your computer of all the same bugs that the more expensive scans can a much lower price. You can’t beat that, keep your computer running great for less. Visit their site at http://www.Search-and-destroy.com to download this scan and get all the benefits it has to offer. If you’re like me, it will be the best decision you made in a long time.