Welcome | Sign In
TechNewsWorld.com
Malware

Skype IM Falls Victim to Trojan Attack

Print Version
E-Mail Article
Reprints
Skype IM Falls Victim to Trojan Attack

An attack that penetrated the Skype instant messaging service was originally identified as a worm, but it is actually a Trojan horse, according to WebSense, the security research firm that discovered the malware. "We don't believe this new Trojan is very widespread, but this attack can cause damage," said Dan Hubbard, vice president of security research at WebSense.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

WebSense on Monday identified a Trojan horse that targets Skype IM users in what marks the latest in a series of instant messaging attacks this year.

The security researcher first reported the attack as a self-propagating worm called "sp.exe." After a full day of investigation in cooperation with Skype and its parent company eBay (Nasdaq: EBAY), WebSense issued an update saying it was a Trojan horse.

Trojan horses are programs that appear harmless, or even helpful, but harbor malicious code used to collect or destroy data.

"What's unique about this Trojan horse is that it uses Skype as its vehicle for propagation," Dan Hubbard, vice president of security research at WebSense, told TechNewsWorld. "But this is not dissimilar to Trojans that have attacked other messaging platforms in the past, like ICQ and Microsoft (Nasdaq: MSFT) Messenger."

Social Engineering 101

The Trojan horse uses the Skype application programming interface (API) to do its dirty work. The end-user who is running Skype receives a message suggesting a file download. Clicking on the link initiates download of the Trojan horse.

Security researchers describe the tactic as social engineering, because it demands interaction from the end-user to spread itself. Social engineering scams typically involve clever schemes that convince users to participate, offering free information or breaking news.

Instant messaging is an attractive platform for malicious users because it works. This time last year, cyber attackers enjoyed success Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales with a holiday-themed worm attack that delivered its malicious payload to IM users of AOL, MSN, Windows Messenger, ICQ and Yahoo.

"We don't believe this new Trojan is very widespread, but this attack can cause damage," Hubbard warned. "The Trojan includes some processes that allow attackers to inject into the explorer process, which usually is used for things like password stealing within forms at eBay and PayPal and other types of sites."

Money Motives

Like a growing number of Internet attacks today, security experts say social engineering-based attacks have one motive: money. Since security technologies are blocking out e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse borne worms and viruses, attackers are turning to browsers and IM platforms to deliver their nasty payloads.

IM presents a unique opportunity for hackers just based on its sheer growth. Enterprise IM will grow from 40 million users today to more than 140 million by 2009, IDC estimates, which makes IM the fastest-growing communications medium of all time.

Because IM operates in real time, attacks that leverage social networking to spread can be highly destructive and costly to a corporate infrastructure.

Worms were the preferred type of malicious code on all three large IM networks in the second half of 2005, representing 91 percent of IM-related malicious code during that period, according to the most recent Symantec (Nasdaq: SYMC) Internet Security Threat Report.

Highly Targeted Attacks

More than 2,400 unique IM and peer-to-peer (P2P) threats were identified in 2005, other research indicates. That amounts to a staggering 1,700 percent increase from the previous year.

The vast majority of those threats were URL-based worms. However, the rise of IM-based phishing attacks, as well as the emergence of other sophisticated malware, complicates IM's risk profile.

"Increasingly, threats are converging across e-mail, Web and IM," Mark Sunner, chief security analyst for MessageLabs, told TechNewsWorld. "Highly targeted Trojan attacks, specifically designed to steal intellectual property from businesses and organizations, increased from one a week to one a day this year."


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network