[an error occurred while processing this directive]

CurzTech News Network


CurzTech News NetworkCurzTech World NewsCurzTech U.S. NewsCurzTech Entertainment NewsCurzTech Political NewsCurzTech Conspiracy NewsYesterday's NewsOffsite Archive

OSAC Item (Printer Friendly Version) Banks Target of 'Bugbear' Invasion
from National Post on Wednesday, June 11, 2003

Canada's five major banks are on a list of financial institutions targeted by the "Bugbear" Internet virus, a damaging application transmitted by e-mail that security experts fear will cripple vast computer networks.

The Federal Bureau of Investigation yesterday said it has accelerated efforts to track down the source of Bugbear after security firms studying the virus discovered the Internet domain names of more than 1,000 global financial institutions written into its code.

A copy of the virus code obtained by the National Post shows that the domain names of TD Canada Trust, the Canadian Imperial Bank of Commerce, the Bank of Montreal, RBC Royal Bank and Scotiabank are included on the list. Representatives of those institutions could not be reached for comment last night.

Brian Czarney, a spokesman for MessageLabs, an e-mail security firm based in New York, said in an interview last night the virus could wreak havoc on infected computers by delivering a "Trojan horse" -- an application that sits on a terminal and detects and records key strokes, allowing a hacker to access personal information entered on Web sites such as credit card numbers and passwords.

"We don't know what its intentions are, but it appears to be nefarious," Mr. Czarney said.

He said the virus will damage any infected computer, but it will launch extra steps if it recognizes the domain name of a user's e-mail address as one of those on its list of the financial institutions. Investigators have not yet determined what those extra actions would be, Mr. Czarney said.

"Banking institutions may be considered to be at greater risk," the computer security firm Symantec said in a statement, although Mr. Czarney said the risk to individual bank accounts is low because client bank information is on secure servers. But the financial institutions could be severely hampered by a virus that spreads throughout their systems, he said.

Sometimes called a "worm" virus because it self-replicates by e-mailing itself to all the contacts listed in an infected computer's address book, Bugbear raised alarms among security experts last week because it was spreading so fast.

Bill Murray, a spokesman with the FBI, said investigators know of at least 200,000 systems with the virus, officially called W32/Bugbear.B-mm. MessageLabs reported last week that it had intercepted more than 35,000 copies of the virus.

"Bugbear.B is likely to be more damaging than any virus seen so far this year," Mark Sunner, MessageLabs chief technology officer, said at the time.

"Not only can Bugbear leach confidential information from an infected machine, but it may also leave a backdoor wide open for hackers to take control of the machine."

The FBI and other agencies are ramping up efforts to track the virus now that banks have been identified as its target, according to Suzanne Gorman at the Financial Services Information Sharing and Analysis Center, a U.S. Internet security organization.

"We've never had something directly targeted to financial institutions such as this," Ms. Gorman said. "It raised a few eyebrows."

But Ms. Gorman said there were "no reports of successful penetration" of computer networks of banks or other financial institutions.

The Bugbear virus arrives in the form of an e-mail message. According to MessageLabs, the message will have an innocuous subject line such as "Hello!", "update", or "Just a reminder." Although some viruses require the user to open an attachment, Bugbear is spread simply by opening the message, the company said.

© Copyright 2003 National Post

[an error occurred while processing this directive]