<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Malware News</title>
	<atom:link href="http://www.malware-news.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.malware-news.com</link>
	<description>Latest internet security news blog</description>
	<pubDate>Mon, 04 May 2009 13:12:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Top 20 malware programs. Conficker is on the 1st place</title>
		<link>http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html</link>
		<comments>http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html#comments</comments>
		<pubDate>Mon, 04 May 2009 13:10:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Conficker]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=453</guid>
		<description><![CDATA[According to the report published today by Kaspersky Lab,it has been detected over 45 190 of unique harmful, advertising and potentially dangerous programs during last month. This digit practically does not differ from a metrics for March.

In a rating of twenty most widespread harmful programs worm Conficker known also as Downadup and Kido continues to [...]]]></description>
			<content:encoded><![CDATA[<p>According to the report published today by Kaspersky Lab,it has been detected over 45 190 of unique harmful, advertising and potentially dangerous programs during last month. This digit practically does not differ from a metrics for March.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/05/malware.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/05/malware.jpg" alt="malware" title="malware" width="272" height="223" class="aligncenter size-full wp-image-455" /></a></p>
<p>In a rating of twenty most widespread harmful programs worm Conficker known also as Downadup and Kido continues to the the leading position. By some estimations, Conficker could infect up to 20 million computers worldwide. The last days this worm has started to form the infected computers in a botnet for distribution of spam emails and spyware.<br />
<span id="more-453"></span><br />
The second string of &#8220;charts&#8221;, as well as one month ago, holds the virus Sality with spyware functionality. This harmful program intercepts the information entered by means of the keyboard, and sends gathered information to malefactors.</p>
<p>It is remarkable that the harmful code CodeBaseExec which first versions have been detected in 2004 has returned to April virus &#8220;twenty&#8221;. The program gets on the PC of a victim through old &#8220;hole&#8221; in a browser of Internet Explorer of versions 5.01, 5.5 and 6.0.</p>
<p>The complete rating of harmful programs for April under the version «Kaspersky&#8217;s Laboratory» looks like this:</p>
<p>1. Net-Worm.Win32.Kido.ih<br />
2. Virus.Win32.Sality.aa<br />
3. Trojan-Dropper.Win32.Flystud.ko<br />
4. Trojan.Win32.Chifrax.a<br />
5. Trojan.Win32.Autoit.ci<br />
6. Trojan-Downloader.Win32.VB.eql<br />
7. Packed.Win32.Krap.b<br />
8. Worm.Win32.AutoRun.dui<br />
9. Exploit.HTML.CodeBaseExec<br />
10. Packed.Win32.Black.a<br />
11. Virus.Win32.Sality.z<br />
12. Virus.Win32.Virut.ce<br />
13. Trojan.JS.Agent.xy<br />
14. Worm.Win32.Mabezat.b<br />
15. Virus.Win32.Alman.b<br />
16. Packed.Win32.Krap.g<br />
17. Packed.Win32.Klone.bj<br />
18. Worm.Win32.AutoIt.ar<br />
19. Exploit.JS.Agent.agc<br />
20. Email-Worm.Win32.Brontok.q</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>A critical hole in Adobe products</title>
		<link>http://www.malware-news.com/a-critical-hole-in-adobe-products.html</link>
		<comments>http://www.malware-news.com/a-critical-hole-in-adobe-products.html#comments</comments>
		<pubDate>Wed, 29 Apr 2009 09:36:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Security holes]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=449</guid>
		<description><![CDATA[A critical vulnerability has been found out in Adobe Acrobat and Adobe Reader, the patch for which does not exist now.

As it is informed, the problem is related to processing of JavaScript code. With help of the document generated in special way malefactors theoretically can organise DoS-attack, provoke emergency end of work of the program [...]]]></description>
			<content:encoded><![CDATA[<p>A critical vulnerability has been found out in Adobe Acrobat and Adobe Reader, the patch for which does not exist now.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/adobe-acrobat-9.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/adobe-acrobat-9-300x220.jpg" alt="Adobe Acrobat vulnerability" title="adobe-acrobat-9" width="300" height="220" class="aligncenter size-medium wp-image-450" /></a></p>
<p>As it is informed, the problem is related to processing of JavaScript code. With help of the document generated in special way malefactors theoretically can organise DoS-attack, provoke emergency end of work of the program or execute  any operations on the remote computer.<br />
<span id="more-449"></span><br />
Adobe has confirmed the existence of the problem, having underlined, that it mentions all delivered versions of Reader and Acrobat packages , including 9.1, 8.1.4, 7.1.1 and earlier updatings. The situation is aggravated with that there were examples of the harmful code on the Internet, allowing to involve vulnerability. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/a-critical-hole-in-adobe-products.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Conficker worm is active again</title>
		<link>http://www.malware-news.com/conficker-worm-is-active-again.html</link>
		<comments>http://www.malware-news.com/conficker-worm-is-active-again.html#comments</comments>
		<pubDate>Mon, 27 Apr 2009 11:22:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=445</guid>
		<description><![CDATA[As mark security experts form Symantec, Conficker step-by-step transforms thousands of infected PCs into zombie network for spam and spyware distribution. The worm loads it&#8217;s code under the name Waledac which unites the infected machines in the botnet.


Employees of Trend Micro underline that the network of zombie computers, formed by Conficker, probably, is one of [...]]]></description>
			<content:encoded><![CDATA[<p>As mark security experts form Symantec, Conficker step-by-step transforms thousands of infected PCs into zombie network for spam and spyware distribution. The worm loads it&#8217;s code under the name Waledac which unites the infected machines in the botnet.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/conficker-worm.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/conficker-worm-300x300.jpg" alt="conficker worm" title="conficker worm" width="300" height="300" class="aligncenter size-medium wp-image-446" /></a></p>
<p><span id="more-445"></span><br />
Employees of Trend Micro underline that the network of zombie computers, formed by Conficker, probably, is one of the most difficult and thought over the history of botnets. The creation of this network proceeds rather slowly, however experts do not eliminate possibility of application the botnet in the organisation of massed attacks and distribution of millions undesirable emails.</p>
<p>Conficker has been detected in November of last year, however the peak of its activity was on the beginning of January. By various estimations, for today the harmful program could infect up to 20 million computers worldwide. For a trustworthy information about authors of worm Conficker the award at a rate of 250 thousand dollars is offered.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/conficker-worm-is-active-again.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Database of startup files</title>
		<link>http://www.malware-news.com/database-of-startup-files.html</link>
		<comments>http://www.malware-news.com/database-of-startup-files.html#comments</comments>
		<pubDate>Fri, 24 Apr 2009 13:06:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=437</guid>
		<description><![CDATA[The new database of startup programs has been published. Each entry in the database is classified according to security risk. (Malware, Suspicious, Infected, Trusted, etc.)


The database currently contains over 90 thousand of autorun items, and is constantly being updated.
Visit CESAM Startup files database
]]></description>
			<content:encoded><![CDATA[<p>The new <a href="http://startups.cesam-antimalware.com">database of startup programs</a> has been published. Each entry in the database is classified according to security risk. (Malware, Suspicious, Infected, Trusted, etc.)</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/startups-database.png"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/startups-database-300x287.png" alt="startups-database" title="startups-database" width="300" height="287" class="aligncenter size-medium wp-image-439" /></a><br />
<span id="more-437"></span><br />
The database currently contains over 90 thousand of autorun items, and is constantly being updated.</p>
<p>Visit <a href="http://startups.cesam-antimalware.com">CESAM Startup files database</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/database-of-startup-files.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Hackers have stolen the data about superexpensive military project of the Pentagon</title>
		<link>http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html</link>
		<comments>http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html#comments</comments>
		<pubDate>Wed, 22 Apr 2009 12:27:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Cybercrime]]></category>

		<category><![CDATA[Hackers]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=433</guid>
		<description><![CDATA[Unknown malefactors managed to receive unauthorized access to the information on the most expensive military project of the Pentagon — a hardly noticeable fighter-bomber of fifth generation F-35 Lightning II.

F-35 Lightning II is being developed by companies Lockheed Martin, Northrop Grumman and BAE Systems within the limits of program Joint Strike Fighter. Project cost is [...]]]></description>
			<content:encoded><![CDATA[<p>Unknown malefactors managed to receive unauthorized access to the information on the most expensive military project of the Pentagon — a hardly noticeable fighter-bomber of fifth generation F-35 Lightning II.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/f35_430.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/f35_430-300x187.jpg" alt="f35_430" title="f35_430" width="300" height="187" class="aligncenter size-medium wp-image-434" /></a><br />
F-35 Lightning II is being developed by companies Lockheed Martin, Northrop Grumman and BAE Systems within the limits of program Joint Strike Fighter. Project cost is estimated in 300 billion dollars.<br />
<span id="more-433"></span><br />
As network sources inform, malefactors managed to penetrate into a computer network of one of participants of the Joint Strike Fighter program and copied several terabytes of information about electronic components and the plane construction. Theoretically this data can simplify development of protection against American fighter of fifth generation.</p>
<p>Attack, presumably, has been carried out from territory of China. It is marked that cybercriminals did not manage to reach the most important information on a fighter as it is stored on computers which are not connected to the Internet. Nevertheless the damage put to program Joint Strike Fighter, can be calculated by millions dollars.</p>
<p>Let&#8217;s notice that computer networks of the governmental departments of the USA regularly are exposed to cyberattacks. Last year the president George Bush even has signed the decree which assumes the essential extension of powers of Agency of national safety of the USA for the purpose of preventing of hacker&#8217;s attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>First botnet based on Apple computers</title>
		<link>http://www.malware-news.com/first-botnet-based-on-apple-computers.html</link>
		<comments>http://www.malware-news.com/first-botnet-based-on-apple-computers.html#comments</comments>
		<pubDate>Tue, 21 Apr 2009 09:20:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Botnet]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=430</guid>
		<description><![CDATA[Security experts from Symantec company inform of appearance of the first botnet, which structure includes computers under control of Apple Mac OS X operating system.

The analysis has shown that creation of new zombie network, named iBotnet, has started in January. The structure of the botnet includes computers infected with malicious program OSX.iServices. This trojan was [...]]]></description>
			<content:encoded><![CDATA[<p>Security experts from Symantec company inform of appearance of the first botnet, which structure includes computers under control of Apple Mac OS X operating system.<br />
<a href="http://www.malware-news.com/wp-content/uploads/2009/04/apple-worm2.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/apple-worm2.jpg" alt="Apple botnet" title="Apple botnet" width="250" height="243" class="aligncenter size-full wp-image-431" /></a><br />
The analysis has shown that creation of new zombie network, named <strong>iBotnet</strong>, has started in January. The structure of the botnet includes computers infected with malicious program <strong>OSX.iServices</strong>. This trojan was distributed as an utility for removal of copy protection of pirated versions of Photoshop CS4 and iWork &#8216; 09.<br />
<span id="more-430"></span><br />
At a rough guess, the iBotnet network can include up to several thousand computers. Some time ago the botnet has been already used by malefactors for the purpose of carrying out of the distributed DoS-attack. Probably in the long term cybercriminals will try to use iBotnet for the organisation of a mass spam distribution. Experts mark that the majority of anti-virus programs for Mac OS X platform already contain detection and removal procedures for the iServices trojan. Users are strongly recommended not to neglect elementary security measures.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/first-botnet-based-on-apple-computers.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>New trojan blocks access to Windows</title>
		<link>http://www.malware-news.com/new-trojan-blocks-access-to-windows.html</link>
		<comments>http://www.malware-news.com/new-trojan-blocks-access-to-windows.html#comments</comments>
		<pubDate>Mon, 20 Apr 2009 07:54:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=427</guid>
		<description><![CDATA[Doctor Web company warns about appearance of the new harmful program locking access to the infected computer.

The trojan was named Winlock.19. The program extends through the Internet under the pretext of counterfeit codecs and suggests to enter the special code ostensibly necessary for registration of a counterfeit copy of the operating system of Windows. To [...]]]></description>
			<content:encoded><![CDATA[<p>Doctor Web company warns about appearance of the new harmful program locking access to the infected computer.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/locked-computer.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/locked-computer-300x207.jpg" alt="locked-computer" title="locked-computer" width="300" height="207" class="aligncenter size-medium wp-image-428" /></a></p>
<p>The trojan was named Winlock.19. The program extends through the Internet under the pretext of counterfeit codecs and suggests to enter the special code ostensibly necessary for registration of a counterfeit copy of the operating system of Windows. To receive this code, it is necessary to send the text message from a mobile phone on a paid number.<br />
<span id="more-427"></span><br />
It is remarkable that Winlock it is supplied by function of self-destruction and deletes itself in two hours after start. The Doctor Web company does not recommend to users to follow the malefactors and to send SMS anywhere. For those who does not wish to wait two hours to an automatic uninstall, Doctor Web has prepared the special form into which it is possible to enter the text of the prospective short message and to receive an unblocking code.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/new-trojan-blocks-access-to-windows.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Conficker worm: new version detected</title>
		<link>http://www.malware-news.com/conficker-worm-new-version-detected.html</link>
		<comments>http://www.malware-news.com/conficker-worm-new-version-detected.html#comments</comments>
		<pubDate>Thu, 16 Apr 2009 09:13:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=424</guid>
		<description><![CDATA[The &#8220;Kaspersky&#8217;s Labs&#8221; warns about appearance of the new version of the Conficker also known as Kido and Downadup.

Conficker has been detected in November of last year, however the peak of its activity has been on the beginning of January: for a few days the worm has infected about ten millions computers worldwide.

New variant of [...]]]></description>
			<content:encoded><![CDATA[<p>The &#8220;Kaspersky&#8217;s Labs&#8221; warns about appearance of the new version of the Conficker also known as Kido and Downadup.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/04/conficker.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/04/conficker-260x300.jpg" alt="conficker" title="conficker" width="260" height="300" class="aligncenter size-medium wp-image-425" /></a></p>
<p>Conficker has been detected in November of last year, however the peak of its activity has been on the beginning of January: for a few days the worm has infected about ten millions computers worldwide.<br />
<span id="more-424"></span><br />
New variant of Conficker has started to extend in the end of last week: the infected computers, co-operating with each other through P2P-connections, have given the command to other infected computers on loading of upgrades and two files — FraudTool. Win32.SpywareProtect2009.s and Email-Worm. Win32.Iksmas.atz. The first of these units represents a counterfeit antivirus which is placed on the servers allocated in territory of Ukraine. At start the program suggests «to delete the found viruses», demanding for it about 50 dollars. The second file — a mail worm possessing a functional of theft of the data and a spam sending.</p>
<p>«Kaspersky&#8217;s labs» marks that for 12 hours one bot infected with the new version of Conficker has sent over 42 thousand spam emails. If to assume that the total amount of infected computers is about 5 million it turns out that the Conficker botnet is capable to dispatch approximately 400 billions spam messages daily.</p>
<p>Different sources also inform that in the end of last week the Conficker has penetrated into computer network of University of Utah (USA), having infected about 700 computers at medical school, medical nursing care college and so forth the Primary analysis of a code of new variant Conficker allows to say that it will function till May, 3rd.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/conficker-worm-new-version-detected.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Next attack of Conficker is expected on April 1st</title>
		<link>http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html</link>
		<comments>http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html#comments</comments>
		<pubDate>Thu, 26 Mar 2009 10:56:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=421</guid>
		<description><![CDATA[On April, 1st worm Conficker, probably, will force not to laugh, and to cry very many Internet users.

Conficker has been detected in November of last year, however the peak of its activity was on the beginning of January: for few days the worm infected about ten millions computers worldwide. The malicious program, capable to extend [...]]]></description>
			<content:encoded><![CDATA[<p>On April, 1st worm Conficker, probably, will force not to laugh, and to cry very many Internet users.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/03/virus_big_300.jpg"><img src="http://www.malware-news.com/wp-content/uploads/2009/03/virus_big_300-253x300.jpg" alt="Conficker" title="Conficker" width="253" height="300" class="aligncenter size-medium wp-image-422" /></a></p>
<p>Conficker has been detected in November of last year, however the peak of its activity was on the beginning of January: for few days the worm infected about ten millions computers worldwide. The malicious program, capable to extend in the various ways, including through removable disk drives, allows malefactors to inspect the infected computers far off.<br />
<span id="more-421"></span><br />
Computer security experts warn that on  April 1st Conficker will receive a certain upgrade. Experts believe that the malicious program can be used for the purpose of the organisation of DDoS-attacks, and also for realisation of a mass spam sending or the infected letters.</p>
<p>Microsoft with support of some the organisations (including OpenDNS) has already launched campaign for struggle against a worm, providing locking of domain names which can be used by the worm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>The worm of new type unites Linux-routers in a botnet</title>
		<link>http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html</link>
		<comments>http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html#comments</comments>
		<pubDate>Wed, 25 Mar 2009 16:30:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[Botnet]]></category>

		<guid isPermaLink="false">http://www.malware-news.com/?p=418</guid>
		<description><![CDATA[Experts from DroneBL have detected very unusual botnet, consisting not from personal computers of Internet users, but from DSL-modems and routers.

According to the research, a worm under the name psyb0t is responsible for the creation of the botnet. Network devices on the basis of Mipsel platform  — variant of Debian Linux for processors MIPS [...]]]></description>
			<content:encoded><![CDATA[<p>Experts from DroneBL have detected very unusual botnet, consisting not from personal computers of Internet users, but from DSL-modems and routers.</p>
<p><a href="http://www.malware-news.com/wp-content/uploads/2009/03/hacker2.png"><img src="http://www.malware-news.com/wp-content/uploads/2009/03/hacker2-300x232.png" alt="hacker2" title="hacker2" width="300" height="232" class="aligncenter size-medium wp-image-419" /></a></p>
<p>According to the research, a worm under the name <strong>psyb0t</strong> is responsible for the creation of the botnet. Network devices on the basis of Mipsel platform  — variant of Debian Linux for processors MIPS are the subject of infection. Attack is made by exhaustive search of combinations of a login and the password under the list; after successful breaking psyb0t closes access to a router for other users and incorporates with the botnet.<br />
<span id="more-418"></span><br />
DroneBL experts mark that they have detected the malicious program during reflexion of the DDoS-attack routed on their servers. The worm, presumably, is unique and extends in the Network from the beginning of the year. At a rough guess, the botnet, organised with the help psyb0t, can consist of more than 100 thousand network devices.</p>
<p>It is informed also that some days ago the botnet has ceased to show activity. However the given information is not confirmed yet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
