Friday, September 10, 2010

Cyber Jihad Group Linked to 'Here you have' Worm

Robert McMillan writes on ComputerWorld:

A fast-spreading e-mail worm that crashed systems Thursday may be linked to a cyber jihad organization called Tariq ibn Ziyad, according to security vendor SecureWorks.

The "Here you have" worm spread like wildfire through some computer networks, bringing e-mail servers down and reportedly disrupting large U.S. organizations including Disney, Proctor and Gamble, Wells Fargo, and NASA (National Aeronautics and Space Administration). It's known as "Here you have" because that is sometimes the subject line of the messages used to spread the malware.

Much of the worm's code is identical to an earlier piece of malware that was released last month, and both worms refer to a Libyan hacker who uses the name Iraq Resistance, who has been trying to form a hacking group called Brigades of Tariq ibn Ziyad, said Joe Stewart, director of malware research with SecureWorks.

"Either this person is involved with this virus, or somebody wants to make it seem like this person's group is involved in this virus," Stewart said. "There are a lot of pointers to that group."

