ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MSN Messenger used for viral gang warfare

Munir Kotadia ZDNet Australia

Published: 08 Mar 2005 09:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Just weeks after Microsoft forced millions of MSN Messenger users to update their client software in order to stop the spread of a worm, the popular instant messenger service is once more being exploited by virus writers.

Antivirus firm Trend Micro has issued a 'medium risk' alert for both the Kelvir.B and Fatso.A worms. Although similar in functionality, the worms are not thought to be connected.

Jamz Yaneza, senior virus researcher at Trend Micro's antivirus labs division, said that the worms spread by sending messages that contain Internet links to malicious bots. Once downloaded, the bots allow an attacker to take full control of the infected computer. The worms send messages to all the infected user's IM contacts that are online.

"The real losers in this game are the end users who are unaware their systems are being infected, or that back doors are being opened to their networks," said Yaneza.

However, the worm writers are not only attacking end users, they are also verbally insulting each other.

According to Trend Micro, the worms contain abusive messages targeted at rival virus writers.

The Fatso.A worm, which can also spread using the eMule P2P file sharing application, contains a text file with a message for 'Larissa', who is thought to be responsible for the Assiral.A worm that was discovered earlier this year. Assiral. A was a 'good' worm — it was designed to search and destroy variants of the Bropia worm, which also used the MSN Messenger service to spread.

On infected systems, the Assiral.A worm displayed the message: "Larissa - Anti-Bropia - Freeing the world of Bropia".

In response, the FATSO worm's message says: "Hey LARISSA f**k off, you f**king n00b!.. Bla bla to your f**king Saving the world from Bropia, the world n33ds saving from you!"

"It sounds comical, but these are like gang members that are tagging neighbourhoods but using malware creations as a vehicle to communicate insults at one another," said Yaneza.

In February, Microsoft forced millions of its MSN Messenger users to download a new version of the software to plug a security vulnerability. The mandatory upgrade began after a security company posted information that would help a would-be attacker exploit the vulnerability. MSN Messenger users were then greeted with a notice to upgrade before they could open their instant messaging clients.

According to a Microsoft spokesperson, the MSN Messenger service will not have to be upgraded or patched this time because the worms rely on user interaction rather than exploiting a programming error.

"These worms do not exploit security vulnerabilities, but rather rely on the user to accept a file and then run it. The worm then sends itself to all the contacts in a user's MSN Messenger contact list," the spokesperson said.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
122 out of 226 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Campaign Manager

Campaign Management Board - Monitors, analyses and reports on performance of campaigns - Leads quarterly Customer Campaign Management Board (CCMB) ...

Java Developer (Senior) Ecommerce, Java, J2EE, EJB, JSP, SQL

Hertfordshire and has offices in US, China and Australia. Excellent communication skills -Excellent delivery focus and commitment -Team players, able ...

SAP Data Migration Analyst needed Global Manufacturer, Manchester

This is very high profile project within an organisation made up of 50,000 people spread across 35 countries. You will be working on the ECC5 version ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment