Skip to content

W32/Zhelatin.CQ worm exploits fear of US war against Iran

F-Secure reports that this Zhelatin variant started spreading a few hours ago, using email Subject: lines such as Missle Strike: The USA kills more then 10000 Iranian citizens (sic).

When a user installs the worm, it attempts to kill antivirus software, establishes a rootkit, and joins its own peer-to-peer network. In order to spread, the worm scans the local hard disks for email addresses, and proceeds to mail itself out in email attachments named e.g. Read More.exe.

External links:

Post a Comment

Your email is never published nor shared. Required fields are marked *
*
*