Marty Kearns is sounding the alarm bells because he received a copy of the new “Beagle” virus with a return address at PoliticsOnline, the online newsletter about e-campaigning. Marty hypothesizes that perhaps hackers are attempting to target online Democratic GOTV organizing efforts.
Now I like a good conspiracy theory as much as the next guy, but it seems to me that the most likely explanation for receiving a virus that appears to be from PoliticsOnline is that someone at PoliticsOnline got the virus via email (bad on them) and that Marty was in that person’s email address book, so the virus emailed itself out to him, faking the return address so that it was from another random user at PoliticsOnline.
If you check the Symantec info on Beagle, you’ll see that it notes that “the from address will be spoofed such that it will appear to come from someone belonging to the same domain as the receiver.”
Spoofed return addresses are very common with email viruses, and the address that a virus email appears to be from doesn’t tell you a thing about where the virus really came from, the intent of the virus sender, or anything else.