ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Email worm graduates to IM

Munir Kotadia ZDNet Australia

Published: 04 Apr 2005 09:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A worm that first disguised itself as an email from computer vendors now attempts to trick MSN Messenger users into executing malicious files.

The Chod.B worm, which was first discovered on April Fool's day, spreads via email purportedly from Microsoft, or security vendors Symantec and Trend Micro.

When using MSN Messenger as its propagation tool, the virus sends out messages to contacts from the infected user's address book, warning them that they are about to receive a file. The virus then sends a file designed to infect the recipient.

Trend Micro’s senior systems engineer Adam Biviano said the development is 'alarming' because it mimics the behaviour of a real IM user.

"The virus will send you a message first saying 'check out what I just found on the Internet', and then send you [the malicious] file. It is not just sending files out of the blue anymore — it is trying to imitate what a friend in your contact list would do," said Biviano.

Chod.B also contains a tool that allows it to steal passwords from a number of IM applications — including AOL, ICQ Lite, Miranda, MSN Messenger, Trillian, and Yahoo Messenger.

Biviano said that because the virus author has also included a way to communicate with the virus, it could mean that in the future the same virus could be instructed to infect more than just MSN Messenger users.

However, even when using e-mail to spread, Chod.B spoofs the 'from' field of the e-mail so it appears to have been sent from either security@microsoft.com, security@trendmicro.com or securityresponse@symantec.com.

According to Biviano, viruses in the past have tried to look like they were sent by Microsoft but this is the first time virus writers have tried to pass off a virus as a message from an antivirus company.

"We have seen them in the past from [Microsoft] but not specifically from the other two addresses. It is just another social engineering attempt to try and trick users into executing the files," said Biviano.

Biviano said although Chod.B is cleverly designed, it is unlikely to become a widespread threat.

MSN Messenger — which has previously been targeted by virus writers — isn't the only instant messaging service to be exploited. Last week, phishers took aim at Yahoo's Messenger service by attempting to steal usernames, passwords and other personal information. The search giant admitted that attackers were sending its users links to fake Web sites that mimicked a Yahoo site and asked the user to log in by entering their username and password.

In fact, security firm Websense has warned that hackers are increasingly using instant messaging applications to fool users into installing malicious code and revealing personal information.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
80 out of 156 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Websphere Developer - Message Broker/MQ - West Midlands

Java / Websphere / Message Broker / SOAP / Webservices. The key technical skills they are looking for are Websphere Message Broker (WMB) as well as ...

Websphere Message Broker Consultant

This client might also require candidates to take part in the build and design of messaging flows there after. My client, a financial insitution ...

2nd/3rd Line Messaging Specalist East London Contract

Blackberry Server Instant messenger experience Server Maintenance VB Scripting (favourable) You will get involved in project work as well as getting ...

Sentry Posts Blog

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Indian officials accuse China of cyber...

China is actively engaged in mapping India's computer networks, according to the Times of India. China is mounting "almost daily" attacks against Indian Government computer systems,... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation