Four new versions of the Bagle e-mail worm appeared on Thursday, and antivirus experts warn that new techniques by the worm’s creator could make it harder to stop the new worm variants.Antivirus companies issued software updates and alerts about Bagle.Q, R, S and T. The new versions of the worm, which first appeared in January, do not carry file attachments containing the virus. Instead, they use a months-old Microsoft Windows security hole to break into vulnerable machines, experts said.“It’s really nasty. Just previewing a message in an e-mail client could download the virus to your computer,” said Graham Cluley, senior technology consultant at Sophos in Abingdon, U.K.The security hole used by the worm is known as the Internet Explorer Object Data Remote Execution vulnerability and concerns a problem with the way the Internet Explorer Web browser interprets HTTP data. The vulnerability, MS03-032, was patched by Microsoft in August, 2003. Previous versions of Bagle have shipped off copies of the virus as e-mail file attachments with ZIP, EXE and SCR attachments, among others.Antivirus and antispam products can block the spread of such viruses by scanning incoming e-mail attachments, identifying the virus file by the name, size and other telltale characteristics. By foregoing file attachments, the Bagle author has made it easier to slip by security products, Cluley said. Like its predecessors, the new Bagle worms arrive in e-mail messages with faked sender addresses and vague subjects such as “Re: Hello,” “Incoming message,” “Site changes,” and “Re: Hi.”When opened or previewed on unpatched Windows systems, the Bagle e-mail message first downloads a computer script with a PHP extension from one of a number of predefined Web servers used by the virus author. After it is downloaded, that script runs and downloads, then runs the actual worm file, said antivirus company F-Secure of Helsinki, Finland.F-Secure researchers have passed the IP addresses of machines that are hosting the virus file to authorities who are shutting them down, said according to Mikko Hyppönen, director of antivirus research at F-Secure.The new Bagle variants prove that the author is continuing to experiment with new techniques to trick security products, said Cluley.“There’s a continuing evolution with Bagle. In the beginning there were regular attachments, then they switched to ZIP files, then encrypted ZIP files with passwords, then passwords stored in graphics files, and now this,” he said.The four new variants are closely related and may indicate some tinkering with the worm’s code to fix problems, Cluley said. “There may be some bugs in the code that limited its success,” he said. Antivirus companies said that the Bagle.Q variant, the first in the latest batch, is the most widespread. F-Secure-rated the Bagle.Q a Level 2 threat, indicating “large infections” within a specific region.F-Secure has recorded infections in more than 20 countries from Bagle.Q, said Hyppönen.Sophos has evidence of particularly heavy infections in South Korea, Cluley said.Antivirus companies posted software updates to detect the new Bagle variants. Computer users were also advised to apply the Microsoft patch, if they had not already done so, to protect against infection by the new Bagle variants. Related content news Broadcom to lay off over 1,200 VMware employees as deal closes The closing of VMware’s $69 billion acquisition by Broadcom will lead to layoffs, with 1,267 VMware workers set to lose their jobs at the start of the new year. By Jon Gold Dec 01, 2023 3 mins Technology Industry Technology Industry Markets news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Network Management Software Network Management Software news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Certifications Certifications news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Mainframes Mainframes Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe