New Santy Variants Learn to Use Yahoo, AOL

CYBERSPACE — The Santy Internet worm, which was discovered last week and used the Google search engine to find vulnerable websites, has evolved to spread via other search engines following Google’s crackdown on the worm’s distribution mechanism.

Net-Worm.Perl.Santy.a, the original version of the worm, targeted phpBB online bulletin boards and searched Google for “viewfiles.php,” which allowed the worm to find versions of the phpBB software earlier than 2.0.11.

“Santy.a is something of a novelty,” Anti-virus firm Kaspersky said at the time. “It creates a specially formulated Google search request which results in a list of sites running vulnerable versions of phpBB.”

Once the virus has located its targets and successfully infected a site, it searches for and overwrites files with .asp, .htm, .jsp, .php, .phtm, and .shtm extensions. In their place, the worm places files which contain the text, “This site is defaced!!! NeverEverNoSanity WebWorm generation.”

Google began filtering search requests soon after the worm was discovered and began to return results only for sites no longer vulnerable to the worm, but new versions of the worm that use AOL and Yahoo search engines began popping up late last week and were announced by the Internet Storm Center on Christmas Day.

The variants, referred to as Santy.b and Santy.c, operate differently than the original worm, according to anti-virus experts.

“It tries to pull several scripts from an affected forum,” wrote the ISC in its daily diary. “The forum could have been compromised and used as a base to attack others.”

Among other features included in the newer versions of Santy are the attempted installation of a bot that would grant an attacker control over the computer and may possibly allow for targeted distributed denial-of-service attacks.

Another new worm, originally referred to as Santy.e, was reported by the Kaspersky, which exploits PHP scripts called “PHP Scripts Automated Arbitrary File Inclusion,” and could be potentially dangerous to any website, even with updated versions of PHP and phpBB.

After an analysis of the worm by Kaspersky, though, the worm was found to contain different mechanisms by which it operated and was renamed to Spyki.b.

The worm was also tagged as being created by Brazilian hacking group Atrix Team.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Mark Spiegler Named XBIZ Talk Guest for 2026 LA Conference

XBIZ is pleased to announce that famed talent agent Mark Spiegler, impresario of the the Spiegler Girls agency, will join an exclusive talk session at XBIZ 2026, the latest edition of North America’s largest adult industry conference, set to take place Jan. 12-15 at the Kimpton Everly Hotel in Hollywood.

Gataca Introduces Passkey Integration

Spain-based age verification provider Gataca has debuted its new passkey integration.

GloryPay Announces New Financial App

European fintech company GloryPay has announced the launch of its financial app for industry members.

Creator of Hentaied, Parasited Launches New Site 'MonsterPorn'

Romero Mr. Alien, the creator of Parasited and Hentaied, has launched new paysite MonsterPorn.com.

House of Lords Approves UK Plan to Outlaw 'Choking' Content

The House of Lords, the U.K.’s upper house of Parliament, has agreed to amendments to the pending Crime and Policing Bill that would make depicting “choking” in pornography illegal and designate it a “priority offense” under the Online Safety Act.

Indiana Sues Aylo Over AV, Calls IP Address Blocking 'Insufficient'

Indiana Attorney General Todd Rokita has filed a lawsuit against Aylo, alleging that the company and its affiliates have violated both Indiana’s age verification law and the state’s Deceptive Consumer Sales Act.

House Committee Amends, Advances Federal AV Bill

A U.S. House of Representatives subcommittee voted Thursday to amend the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law, and to advance the bill for review by the full Committee on Energy and Commerce.

New AI Companion Platform 'SinfulXAI' Launches

SinfulXAI, a new AI companion platform, has officially launched.

FSC Reveals Results of 2026/2027 Board of Directors Election

The Free Speech Coalition (FSC) has announced the results of its 2026/2027 Board of Directors election.

Report: AVS Group Beefs Up AV After $1.3 Million Fine

Adult content provider AVS Group has begun to institute robust age checks on some of its websites after U.K. media regulator Ofcom last week imposed a penalty of approximately $1.3 million for noncompliance with Online Safety Act regulations, the BBC is reporting.

Show More