The new virus made its debut on the Internet on Friday (18 March), clogging bandwidth, stealing personal data and initiating denial of service attacks.
Phatbot is a variant of a Agobot, a big family of IRC bots. It can steal personal information such as email addresses, credit card numbers, PayPay details and software licensing codes. It forwards this information using a peer-to-peer (P2P) network, rather than IRC channels exploited by its predecessors. Earlier versions of the bug go by monikers such as Phat, Backdoor.Agobot.fo and Gaobot, according to F-Secure.
Phatbot can also kill any anti-intrusion devices and give people a false sense of security in order to get inside a network and exploit vulnerabilities, F-Secure says.
Phatbot inserts backdoors which can be used to perform distributed denial of service (DDoS) attacks aimed at shutting down Web sites including those of German Internet hosting company Schlund, US telecoms firm XO and Stanford University. The bug also terminates processes belonging to competing malware such as MSBlast.