Newsletter:

Skip Navigation LinksHome > News > Security > Bagle still the malware boss

Bagle still the malware boss

By Clement James
12 March 2007 09:57AM
Tags: bagle | still | malware | boss

Three years on and email worm still going strong.

Veteran malware Bagle continues to defeat most antivirus solutions almost three years on by using a cleverly devised distribution method, security experts warned this week.

The email worm has begun to use key offensive strategies to maximise propagation and slip under the radar of traditional antivirus defences, according to a report from security firm Commtouch.

Bagle, also known as Beagle, is one of the longest running examples of email-borne malware.

The worm has seen continued success from its high distribution intensity, releasing thousands of infected email messages a day to ensure a wide distribution of the malware across the internet.

Bagle also has a vast number of variants. Over 30,000 distinct variants were detected during the report period. 

As each variant, or group of variants, requires a different signature, it is virtually impossible for antivirus engines to keep up with this rapid-fire pace.

Moreover, each variant is distributed in very small quantities or instances. Since an antivirus vendor must be aware of a malware sample in order to analyse it, distribution in low numbers often enables Bagle to "fly below the radar" of traditional antivirus engines.

"The recent burst of 30,000 new distinct variants shows that Bagle has adopted the server-side polymorphic form and is sending intense waves of variants," said Haggai Carmon, vice president of products at Commtouch.

"Most email malware, including Bagle, has adopted this technique to penetrate traditional antivirus solutions by exploiting their signature time lag."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(6829) -  top
(3293) -  microsoft
(2305) -  broadband
(2170) -  content
(2132) -  company
(2129) -  data
(1915) -  terria
(1859) -  isp
(1813) -  nbn
(1725) -  filtering
(1698) -  telstra
(1585) -  internode
(1542) -  voip
(1445) -  centre
(1212) -  consumers