Homer Simpson
Homer Simpson has become the latest malware mover
R E L A T E D   C O N T E N T
ADVERTISEMENT

Homer Simpson spreading malware

Web 2.d'oh!

Shaun Nichols in San Francisco, vnunet.com 12 Jul 2008
ADVERTISEMENT

A screen name once connected to animated TV dad Homer Simpson is being used to spread malware.

A 2003 episode of The Simpsons revealed that Homer's email address was chunkylover53@aol.com.

The address was registered by one of the show's writers prior to the episode's airing and used to answer hundreds of emails from Simpsons fans.

But the chunkylover53 screen name has resurfaced and is now being used to distribute a Trojan disguised as a Simpsons movie file.

Chris Boyd, malware research director at FaceTime, said that chunkylover53 is sending auto-reply messages promising a special exclusive episode of the show available for download.

The link in the message leads to an executable file. On launching the Trojan, the user is presented with a fake error message followed by several real error messages and finally a blank screen.

On restarting, the user's system will run noticeably slower and be prone to crashes.

The malicious payload includes a rootkit and remote control software which logs the user in a botnet. The malware was traced back to Kimya, a Turkish botnet which has been infecting machines for the past four months.

Boyd told vnunet.com that it was unclear whether the malware operators have taken control of the chunkylover AOL account, or simply registered the screen name as an instant messenger account. AOL did return a request for comment.

The malware is currently being spread only by the chunkylover53 user name, but Boyd warned that the botnet could easily be used to launch a much larger malware attack in the future.

"For now, this is a good reminder to be cautious when randomly adding cool things seen on TV and film to your online applications," said Boyd.

"You cannot always assume that the person at the other end is entirely in control, or indeed related to what you are looking for in the first place."

See also:

SpamLatest scam offers 'video' of US troops invading Iran  09 Jul 2008
HackerAdware giving way to more serious threats  08 Jul 2008
Stars and StripesSecurity firms warn users to take extra care  04 Jul 2008
World of WarcraftPassword stealing malware hits US and Turkey  02 Jul 2008

All Hacking
Tags: Malware, Botnet, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Cherwell, Oxfordshire, United Kingdom | Cherwell District Council
Customer Service and Resources Systems Support and Development Officers £29,355 per annum Local Grade 15   Cherwell District Council uses a range of significant business systems to help deliver its services to internal and external ... more >
Sandiacre, Nottinghamshire, United Kingdom | NHS Midlands
Workstream Lead Requirement, Design, Build and Test (Business Analyst) Strategic IM&T - Delivery   Band 7:      £29,091 - £38,352 per annum Hours:       37.5 per week Base:         Octavia House, Sandiacre Job Ref:     973 - 080810   ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOE Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
More job opportunities