NEWS FROM THE LAB - Tuesday, March 16, 2004

Update on the war between Bagle and Netsky worm authors. Posted by Alexey @ 14:44 GMT

After checking the latest Bagle and Netsky worm variants we have come to the following conclusions:

1. Now the Netsky worm is most likely manufactured by another person/group. A message inside the latest Netsky.N worm indicates that a new person/group has acquired the source code of the worm and they are going to continue the war against Bagle and Mydoom authors. The war was started by the original Netsky worm authors.

2. The latest variants of Bagle worm started to kill processes of Netsky worms and began to delete Netsky's startup keys from System Registry. This indicates that the person/group behind Bagle worm has joined the war against Netsky. The latest Bagle variant deletes startup keys of many Netsky worm variants and kills a process of at least one Netsky variant - Netsky.M.

Bottom line: In the future we are most likely going to see new Netsky and Bagle variants regularly until people creating them give up or get arrested.