A new JavaScript worm targeting Yahoo!’s email program has been found in the wild by Symantec Security Response today.

Symantec said the worm, JS.Yamanner@m, spreads itself to a user’s Yahoo! email contacts when the user opens an email infected by the worm. JS.Yamanner sends these email addresses to a remote server on the Internet.

“This worm is a twist on the traditional mass-mailing worms that we have seen in recent years. Unlike its predecessors, which would require the user to open an attachment in order to launch and propagate, JS.Yamanner makes use of a previously-unknown security hole in the Yahoo! Web mail program in order to spread to other Yahoo! users and harvests user information for possible future attacks,” said Symantec Security Response Director, Dave Cole. 

Only those using contacts with an email address that is @yahoo.com or @yahoogroups.com are affected by the worm. Yahoo! Mail Beta users are not vulnerable to JS.Yamanner.

A message from JS.Yamanner can be distinguished by the following:
From: av3@yahoo.com
Subject: New Graphic Site
Body: this is test.

Also, if users open an infected email, their browser window is re-directed to display the Web page with URL: www.av3.net/index.htm.

JS.Yamanner is currently categorised as a Level 2 (out of five) threat by Symantec Security Response.

The company said that since a Yahoo! patch is unavailable, updating anti-virus definitions and deleting any emails received from av3@yahoo.com is highly recommended.

See: http://securityresponse.symantec.com/

728X90 Yahoo! Email Worm Emerges
728x90 Yahoo! Email Worm Emerges
ARLO MG3 2024 Banner 728x90px scaled Yahoo! Email Worm Emerges
iP16 4SQRmedia 970 x 90 px 03 Yahoo! Email Worm Emerges
PAN2664 ChannelNews Banner CM3 728x90px V1 Yahoo! Email Worm Emerges
05 Channel New Banner T30S COMBO 728x90 Yahoo! Email Worm Emerges
Emberton III BLACK 728x90 without CTA@2x Yahoo! Email Worm Emerges
JBL TourPro3 728x90 Yahoo! Email Worm Emerges
denon perl white 728x90 1 Yahoo! Email Worm Emerges
Haier 728x90 1 Yahoo! Email Worm Emerges
FA 979 HN MDF SG14 14gen 728x90 1 Yahoo! Email Worm Emerges
BlueAnt 4SQM PumpAirUltra 728x90px Yahoo! Email Worm Emerges
728x90 Yahoo! Email Worm Emerges
Leaderboard 728x90 1 Yahoo! Email Worm Emerges
Olimpia Splendid Unico Cooling 728x90 1 scaled Yahoo! Email Worm Emerges
240215 SAV R Volution CNewsFeb Leaderboard 1 Yahoo! Email Worm Emerges
Belkin Screen Protection 728 x 90 Yahoo! Email Worm Emerges
Westan 728x90px Yahoo! Email Worm Emerges
728x90 yoga pro 7i Yahoo! Email Worm Emerges
728x90 we see oled CN Yahoo! Email Worm Emerges
WEB BANNERS5 scaled Yahoo! Email Worm Emerges
Litheaudio 728x90 Yahoo! Email Worm Emerges