<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Virus</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The &#8220;Crab Group&#8221; virus dissemination family</title>
		<link>http://www.thedarkvisitor.com/2009/02/the-crab-group-virus-dissemination-family/</link>
		<comments>http://www.thedarkvisitor.com/2009/02/the-crab-group-virus-dissemination-family/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 11:24:37 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Crab Group]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1388</guid>
		<description><![CDATA[According to Kingsoft Anti-Virus, the &#8220;Crab Group&#8221; is one of China&#8217;s top-5 virus dissemination families and responsible for the recent infection of around 30 million computers. Kingsoft&#8217;s 2008 Year-End report reveals that within hacker circles, the majority of money is earned by establishing viral dissemination chains.  While a virus author may earn a salary of [...]]]></description>
			<content:encoded><![CDATA[<p>According to <em>Kingsoft Anti-Virus</em>, the &#8220;Crab Group&#8221; is one of China&#8217;s top-5 virus dissemination families and responsible for the recent infection of around 30 million computers.</p>
<p><em>Kingsoft&#8217;s </em><a href="http://chinanews.com.cn/it/itxw/news/2009/02-24/1575506.shtml">2008 Year-End report</a> reveals that within hacker circles, the majority of money is earned by establishing viral dissemination chains.  While a virus author may earn a salary of one million yuan a year (approx USD 150,000), it was possible for a viral dissemination group to earn ten million yuan (approx USD 1.5 million) yearly.</p>
<p>The Crab Group had gained access to a unidentified trusted server in Guangdong, uploading viruses and trojans on popular websites.  The group had been using the &#8220;<a href="http://eschina.info/Article_Print.asp?ArticleID=11953">Cat Ringworm</a>&#8221; virus, a.k.a <a href="http://www.thedarkvisitor.com/2009/02/charging-bull-and-chinese-vampire/">Charging Bull</a>, as their primary dissemination tool and infected around 30 million computers.</p>
<p>For background on the Chinese hacker virus industry chain read <a href="http://www.thedarkvisitor.com/2008/05/chinese-hacker-virus-industry-chain/">here</a>, <a href="http://www.thedarkvisitor.com/2008/03/hortonfour/">here</a>, and <a href="http://www.thedarkvisitor.com/2008/03/member-of-national-peoples-congress-calls-for-crackdown-on-chinese-hacker-underground-virus-industry/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/02/the-crab-group-virus-dissemination-family/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The E-Rose Virus by any other name&#8230;</title>
		<link>http://www.thedarkvisitor.com/2009/02/the-e-rose-virus-by-any-other-name/</link>
		<comments>http://www.thedarkvisitor.com/2009/02/the-e-rose-virus-by-any-other-name/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 00:32:17 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Valentine'd Day]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1352</guid>
		<description><![CDATA[Jiangmin Anti-Virus is warning that the E-Rose Virus is making the rounds this Valentine&#8217;s Day.  In 2006, China had the largest number of computers infected from the spread of this malware.]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.usaflorist.com/large/1ROSE.jpg"><img class="aligncenter" title="E-Rose Virus" src="http://www.usaflorist.com/large/1ROSE.jpg" alt="" width="250" height="282" /></a></p>
<p><em>Jiangmin Anti-Virus</em> is warning that the <a href="http://www.stdaily.com/gb/stlifedaily/2009-02/14/content_908911.htm">E-Rose Virus</a> is making the rounds this Valentine&#8217;s Day.  In 2006, China had the <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SETROX.A&amp;VSect=S">largest number of computers infected</a> from the spread of this malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/02/the-e-rose-virus-by-any-other-name/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chinese New Year text messages: &#8220;Extreme Danger&#8221;</title>
		<link>http://www.thedarkvisitor.com/2009/01/chinese-new-year-text-messages-extreme-danger/</link>
		<comments>http://www.thedarkvisitor.com/2009/01/chinese-new-year-text-messages-extreme-danger/#comments</comments>
		<pubDate>Sun, 25 Jan 2009 18:09:04 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[cell phone]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1106</guid>
		<description><![CDATA[From: 022net.com Do you send text messages to your friends, colleagues and customers wishing them well or a Happy New Year?  The answer for the majority of people is, definitely.  Recently, I&#8217;ve received many text messages, all in regards to wishing me well and Happy New Year. With the New Year approaching, the cell phone [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="attachment wp-att-1107" href="http://www.thedarkvisitor.com/2009/01/chinese-new-year-text-messages-extreme-danger/happy2009/"><img class="size-full wp-image-1107 aligncenter" title="happy2009" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/01/happy2009.jpg" alt="happy2009" /></a></p>
<p>From: <a href="http://www.022net.com/2009/1-25/485545352297275.html">022net.com </a></p>
<p>Do you send text messages to your friends, colleagues and customers wishing them well or a Happy New Year?  The answer for the majority of people is, definitely.  Recently, I&#8217;ve received many text messages, all in regards to wishing me well and Happy New Year.</p>
<p>With the New Year approaching, the cell phone virus has entered a period of &#8220;extreme danger,&#8221; so remind your friends to be on the lookout for spam text messages.</p>
<p>Fortunately all you have to do with spam text messages is delete them but they are no joke.  A viral outbreak can cause the cell phone to stop working,  data loss, spread junk mail and dial out to other phones.  It can also destroy hardware such as the SIM card and chip.</p>
<p>(In here how to defend against viral text messages, not translated.  Skipped to more interesting portion of the article)</p>
<p>Capital media reports that cell phone user Mr. Zhang received a pornographic text message from an unknown number, after opening the text, his cell phone continuously sent messages to people stored in his contact list.  The text message harmed the reputation of over 700 people.  Victims sent their cell phones to the service center in order to remove the virus, costing over 200 yuan.  A security expert said the virus contained a website address and transmitter virus.   After the virus is installed, there is no immediate abnormal behavior but after 30 minutes the virus links to the net and transmits text messages every 10 seconds.  Sending out text messages at this high rate can run up user fees.  It is possible the virus is also able to subscribe users to certain unwanted services, driving up charges.</p>
<p>According to <em>China Mobile</em>, the company blocked over 4 billion pieces of junk mail in the first half of 2008.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/01/chinese-new-year-text-messages-extreme-danger/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PLA armor brigade exercise fails due to computer virus</title>
		<link>http://www.thedarkvisitor.com/2008/11/pla-armor-brigade-exercise-fails-due-to-computer-virus/</link>
		<comments>http://www.thedarkvisitor.com/2008/11/pla-armor-brigade-exercise-fails-due-to-computer-virus/#comments</comments>
		<pubDate>Sun, 16 Nov 2008 16:30:24 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Other attacks]]></category>
		<category><![CDATA[armor brigade]]></category>
		<category><![CDATA[PLA]]></category>
		<category><![CDATA[resupply]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=742</guid>
		<description><![CDATA[According to news.ifeng, an unidentified PLA armor brigade was the victim of a computer virus that caused electronic ammunition resupply orders to show up blank. During the force-on-force, Red and Blue exercise, operations were hampered due to a computer virus that left the main attack force without ammunition resupply. During the exercise, the Red Army [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/armor.jpg"><img class="size-medium wp-image-743 aligncenter" title="armor" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/armor.jpg" alt="" width="337" height="250" /></a></p>
<p>According to news.ifeng, an unidentified <a href="http://news.ifeng.com/mil/2/200811/1115_340_879548.shtml">PLA armor brigade was the victim of a  computer virus</a> that caused electronic ammunition resupply orders to show up blank.  During the force-on-force, Red and Blue exercise, operations were hampered due to a computer virus that left the main attack force without ammunition resupply.</p>
<p>During the exercise, the Red Army basic command post, command and control station, received information from the main attack force that 3/4 of their ammunition had been depleted.  A resupply order was immediately sent to the rear command post.  However, after transmission, the order form appeared blank.</p>
<p>Ten minutes later, the main attack force once again sent a request for ammunition resupply.  They were told to wait, that the request for resupply had already been processed.  In the end, the main attack force had no hope of getting their ammunition.  The ammunition was exhausted, people died and the exercise was lost.</p>
<p>NOTE: When the article states that people died, they are speaking in terms of the exercise.  There were no actual fatalities.</p>
<p>It was later determined that the exercise failure was brought on by unpatched computer terminals that allowed a virus into the system.  In response, the armor brigade established a comprehensive network security group and procedures for handling computer security issues.</p>
<p>Li Jintai, the commander of the armor brigade, located in the Guangzhou Military Region, commented, &#8220;when you sharpen your sword, you must not forget to cast your shield.&#8221;   Commander Li further stated, &#8220;Due to patches not being installed, the infecting virus led to the failure of the exercise and this sounded alarm bells for us.  When you sharpen your sword, you must not forget to cast your shield.   Network technology provides the prerequisite for &#8216;informationized&#8217; combat, it raises command efficiency.  However, if there is insufficient importance attached to information security, a lack of network defense consciousness and methodology, it can leave a crack that your adversary can take advantage of and lead to grave consequences.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/11/pla-armor-brigade-exercise-fails-due-to-computer-virus/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Chinese hacker virus industry chain</title>
		<link>http://www.thedarkvisitor.com/2008/05/chinese-hacker-virus-industry-chain/</link>
		<comments>http://www.thedarkvisitor.com/2008/05/chinese-hacker-virus-industry-chain/#comments</comments>
		<pubDate>Tue, 13 May 2008 02:01:39 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[chinese hacker]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=538</guid>
		<description><![CDATA[Used this chart was from IT Rising&#8217;s 2007 report on the computer virus epidemic: To create this crappier but English version of the chart:]]></description>
			<content:encoded><![CDATA[<p>Used this chart was from IT Rising&#8217;s 2007 report on  the computer virus epidemic:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/chart2.jpg"><img class="alignnone size-medium wp-image-539 aligncenter" title="chart2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/chart2-300x258.jpg" alt="" width="300" height="258" /></a></p>
<p>To create this crappier but English version of the chart:</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/chart.jpg"><img class="alignnone size-medium wp-image-540 aligncenter" title="chart" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/chart-300x275.jpg" alt="" width="300" height="275" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/05/chinese-hacker-virus-industry-chain/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

