Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Symantec Security Response's blog

10 Feb 2012 |

Recently there have been several reports about the re-emergence of a botnet variant (Kelihos), which Symantec detects as W32.Waledac.C.

0 comments
01 Feb 2012 |

For quite some time, we have observed the technique of server-side polymorphism being used to infect Windows computers around the world. What this means is that every time a file is downloaded, a unique version of the file is created in order to evade traditional signature-based detection.

0 comments
30 Jan 2012 |

Last week, we posted a blog informing Android users of the discovery of new versions of Android.Tonclank, which we have named Android.Counterclank.

0 comments
26 Jan 2012 |

The Sykipot campaign has been persistent in the past few months targeting various industries, the majority of which belong to the defense industry. Each campaign is marked with a unique identifier comprised of a few letters followed by a date hard-coded within the Sykipot Trojan itself.

0 comments
13 Dec 2011 |

Thanks to Masaki Suenaga and Andy Xies for their analysis.

0 comments
12 Dec 2011 |

Authored by Tony Millington and Gavin O’Gorman

The intercepted email in this blog was provided by Symantec.cloud.

0 comments
06 Nov 2011 |

In late September 2011, it was reported that a previously unknown and un-patched vulnerability in Hancom Office (a word processing software predominantly used in Korea) was exploited in the wild.

0 comments
21 Oct 2011 |

As mentioned in our previous blog, W32.Duqu was first brought to our attention by a research lab who had been investigating a targeted attack on another organization.

0 comments
18 Oct 2011 |

On October 14, 2011, a research lab with strong international connections alerted us to a sample that appeared to be very similar to Stuxnet. They named the threat "Duqu" [dyü-kyü] because it creates files with the file name prefix “~DQ”.

0 comments
19 May 2011 |

W32.Qakbot is a worm that's been around since at least 2009. The worm initially infects users by exploiting vulnerabilities when certain Web pages are visited. It subsequenly spreads through network shares and removable drives.

0 comments