Sophos

Talk to our experts

Find your local press contact

Resources

Info feeds

What are info feeds?

18 March 2003

Swedish computer worm lures with Iraq spy satellite photos

Satellite photo of Iraq

Sophos researchers report that they have discovered a new email-aware worm that feeds on public interest in the imminent war in Iraq in an apparent attempt to lure unsuspecting users.

The W32/Ganda-A worm, which appears to have been written in Sweden, uses a variety of different email subject lines and message bodies to try and encourage computer users to run its viral attachment.

The worm can use a variety of different subject lines and message bodies, in both English and Swedish, including:

"At a time of international crisis it is understandable that computer users will be interested in finding out the latest news from the Middle East, and many may be tempted to share breaking news with their friends and colleagues via email," said Graham Cluley, senior technology consultant for Sophos Anti-Virus. "The author of this virus is exploiting interest in current affairs by deliberately presenting his virus in this way. The message to users is simple: be suspicious of all unsolicited emails."

In a bizarre twist, the author of W32/Ganda-A claims to have a grievance with the Swedish educational system. Hidden inside the virus is the following text:

"We don't know what Uncle Roger's problem is with the school system in Sweden," continued Cluley. "But whatever his problem is a worm is not an appropriate way to complain about it."

Sophos recommends companies consider blocking all Windows programs at their email gateway. It is rarely necessary to allow users to receive programs via email from the outside world. There is so little to lose, and so much to gain, simply by blocking all mailed-in programs, regardless of whether they contain viruses or not. Sophos MailMonitor for SMTP not only detects known viruses but also contains pro-active threat reduction technology which can help businesses block dangerous filetypes and executable code at the email gateway.

Sophos customers who have kept their anti-virus software up-to-date are automatically protected against W32/Ganda-A. Users of other anti-virus products are recommended to update their software.

See also: