With some nine million computers infected, the Kido worm (or Conflicker, or Downadup) has hit hard. However, although it’s spread widely, so far it hasn’t actually done anything.
According to AP, that’s led some researchers to think it might be a dud. F-Secure thinks it might simply offer alerts to fake infections then try to sell users antivirus software. However, F-Secure’s chief research officer, Nikko Hypponen warned:
"The gang behind this worm haven’t used it yet. But they could do anything they like with any of these machines at any time."
Although no one knows exactly where the worm originated, F-Secure says it’s coded not to infect machines in the Ukraine, leading to strong speculation that it originated there.