Researchers have identified a new self-replicating malware that infects computers running the Apache Tomcat Web server, with a backdoor that can be used to attack other machines.
Java.Tomdep, as the worm was named, is Java Servlet-based code that gives Apache Tomcat platforms malicious capabilities. It causes infected machines to maintain Internet Relay Chat (IRC) communication with attackers' servers located in Taiwan and Luxembourg. The control servers send commands and receive progress reports to and from the infected machines. Platforms affected include versions of Linux, Mac OS X, Solaris, and most supported versions of Windows.
In a blog post published Wednesday, Takashi Katsuki, a researcher at Symantec, said Java.Tomdep appears to be designed to exploit the vast amounts of bandwidth and computing power on Web servers for use in denial-of-service attacks against other machines. Unlike Darkleech and other malware that targets Web servers, there is no indication that it is used to attack end users visiting websites.
