Jonathan Richards
Download 'Too Hot', an exclusive Specials track from iTunes
Comment: The silent danger of a clever Trojan
A popular travel website based in Croydon is one of hundreds of sites to have been attacked by a mysterious virus that is sweeping across the internet.
Directline-holidays, which offers cheap package holidays, is one of at least 200 sites - many UK-based - to be affected by a sinister computer virus, the likes of which security firms have never seen.
The virus, which was first detected late last year, attacks the computers of people who visit affected sites by installing a piece of software known as a Trojan, which is capable of stealing information and feeding it back to the attacker.
Unlike other viruses of its sort, the new program does not leave 'footprints' on affected sites, meaning that tracking its path across the internet is much more difficult.
"This attack is unlike anything we've seen," Mary Landesman, a researcher at the security firm ScanSafe, which has been helping one of the UK companies affected, said. "We've worked with one company that's been affected to completely rebuild their server from the ground up, and an hour later the problem came back."
ScanSafe said it estimated the number of websites affected to be 200, but two other companies - Finjan and Secure Works - believe the number could be as high as 10,000.
The sites affected were mostly "mom and pop" sites based in the UK running businesses in areas like travel, property and motoring, Ms Landesman said. They still attracted large numbers of visitors, however, because they performed well in search results.
One site listed by ScanSafe as having been compromised rents cottages in Yorskshire. Another provides replacement parts for Vauxhall cars.
A spokesman for Directline-holidays, which attracts 80,000 customers a day and is the top listed site in a Google search for 'cheap holidays', confirmed that one of the site's technical staff had noticed its servers had been behaving abnormally a week ago.
On analysis, the company discovered that the server had been targeted by a version of a virus "that most security software didn't recognise."
The server has now been removed and the remainder are unaffected, the spokesman said, adding that the site was hosted on one of the largest hosting services in the US.
"This is going to be an extraordinarily long-lived attack, because the evasion technique makes it so hard to take down," Don Jackson, a senior security researcher at SecureWorks said. "The underground hacker community is extolling its virtues and praising whoever came up with it."
It is unclear where those behind it were based, experts said, though the virus did not match any typical "attack patterns" of well-known Russian or Chinese groups.
Computer users were at risk, researchers warned, because many anti-virus programs were not capable of detecting 'dynamic' viruses such as this, which constantly changed their form.
Typically when a website is compromised, hackers install additional files on the site's server, directing a visitor's computer to do particular things when it lands on the site. Once these files are located, researchers can search for similar instances of them across web, enabling all affected site owners to be notified.
In this case, the site is hacked in such a way that only when a person visits the page are the malicious files installed on the site, meaning that they are otherwise undetectable to the company hosting it.
"We call it an 'on-the-fly' Trojan," Mikko Hypponen, chief research officer at the web security company F-Secure, said. "It's definitely a much more complex operation than we're accustomed to."
It is understood that only Windows users are affected by the virus.
Mr Hypponen urged computer owners to regularly update their virus protection, and always to download the latest version of browsers and other applications, such as media players, when prompted.
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the power of collective thinking. Submit a solution and be in with a chance to win a Media Hub Home Entertainment System
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
per month on 36-month
Personal Contract Hire (PCH)
2008
42850
Car Insurance
£24,250 - £30,346
MI5
London
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Fabulous Cruise And Cruise & Stay Offers Including Virgin Atlantic Flights Prices Start From Only £699pp!
Last Minute Cruise And Cruise & Stay Offers. Med From £499pp, Caribbean From £699pp!
5 star quality at a 3 star price.
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Please be careful when asked by a site to download somrthing as contrary to your advice some site download viruses by asking you to download the "latest" or that you need an additional module to your existing programme as I found out by mistake. Only download from trusted sites. If in doubt go to microsoft's own site.
Ernie Goody, Haverhill, Suffolk, UK
Skynet has become aware...
Max, Sydney, Australia
this seems to have affected 2 of our office PC's and the 2 we have at home
Andrew, Caerphilly, wales