NEWS FROM THE LAB - Tuesday, November 22, 2005

Sober.Y becoming huge Posted by Mikko @ 22:14 GMT

fbi warning on soberWe just took Sober.Y to a Radar Level 1 alert. Level 1 is the highest alert we have. And this is the first Level 1 alert we've done in months.

Several millions of infected emails have been seen by internet operators over the last hours.

One of the reasons why this email worm seems to be so successful in spreading is that some of the messages it sends are fake warnings from FBI, CIA or from the German Bundeskriminalamt (BKA). FBI has even put out a a public warning on the case.

First Sober was found in October 2003, over two years ago. We believe all 25 variants of this virus have been written by the same individual, operating from somewhere in Germany. Unlike most of the other widespread viruses nowadays, Sober doesn't seem to have a clear financial motive behind it.

Some Sober variants have displayed neo-nazi messages, but the latest version of the virus does not do this. However, all Sober variants send German messages to German email addresses and English messages to other addresses.

The numbers we're now seeing with Sober.Y are just huge. This is the largest email worm outbreak of the year - so far!