Hmm...
Trend Micro confirms the part about targeting sco.com. I'd visit the official Sco site to see what they had to say, but oops! It's down.
Besides just targeting sco.com, though, it also "runs a backdoor component, which it drops as the file SHIMGAPI.DLL. The backdoor component opens port 3127 to 3198 to allow remote users to access and manipulate infected systems."
So in addition to targeting sco, the creators don't have a problem with being regular hackers and hurting everyone else unrelated to sco as well...