ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Instant messaging attacks rise in 2005

Tom Espiner ZDNet.co.uk

Published: 10 Jan 2006 16:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security attacks over instant-messaging (IM) networks became more prevalent in 2005, according to a study published on Monday.

The MSN network experienced the largest number of IM security incidents in both 2004 and 2005, while year-on-year incident growth rates were largest on AOL's AIM network, according to the report, from IM security vendor FaceTime Communications.

In 2005, MSN had a 57 percent share of the attacks, AOL had 37 percent, and Yahoo had 6 percent, FaceTime said in its IMpact report: Analysis of IM & P2P Threats in 2005.

While the incidence rate of attacks over IM is still low compared with email-borne attacks, the rate is increasing rapidly. There were 778 incidents recorded in the fourth quarter of last year compared with 59 in the first quarter, according to the report.

"IM threats are extremely challenging for corporate IT staff because they utilise real-time communications channels and proven social engineering techniques over worldwide IM networks to propagate significantly faster than email-based attacks," FaceTime said in a statement.

Worms and rootkits were at the heart of the main incidents in 2005, according to Chris Boyd, security research manager of FaceTime, who also warned of the growing danger of cross-network attacks.

"Hacker groups are getting more sophisticated, and are beginning to attack across multiple networks. In 2004 AOL experienced the most attacks, but in 2005 there were more crossovers from AOL to the MSN network, as MSN became more popular with users," said Boyd. "There's some really nasty stuff coming through the AOL network, and it's AOL that's being used as a jump off for other networks."

FaceTime explained that exploits can jump networks through IM "consolidation" applications, such as Trillian or Gaim, that let users combine contacts on multiple IM networks in one list.

Boyd also warned that the hackers are working on new exploits: "Hacker groups have large [compromised] server farms to experiment with propagating exploits. They hide Trojans and viruses, and control these botnets via IRC."

MSN declined to comment specifically on the FaceTime statistics, but agreed that the threat posed by IM was increasing.

"Unfortunately, over the last year the industry has seen viruses and other online threats spread through IM systems, often via Web site links," said an MSN spokesperson. "We recommend that customers do not click on attachments or links in IM without confirming their validity with the person who sent them."

AOL had not commented on FaceTime's statistics at the time of writing.

FaceTime warned last November that one hacker group had taken control of 17,000 PCs using an IM worm, and Boyd confirmed that this area was still causing problems.

"The main and nastiest infections come from the Middle East — we've found a viper nest of hacker dens there," said Boyd. "We've found that lots of hardcore Middle Eastern hacker groups have embraced IM as a launch pad for attacks. They share common knowledge in Arabic to a high degree."

The motivation for these attacks isn't financial, he claimed: "For these gangs, financial gain is less important than making serious political statements. They engage in Web page defacement, and some claim the war as motivation," said Boyd. "The FBI is involved — they've looked at the data we've collected and have used it as a basis for investigation."

The FBI could not confirm or deny whether the data had been passed to them. "We encourage individuals and organisations to come forward to report any suspected crime, but provide confidentiality for them," an FBI spokesperson said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
71 out of 166 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Information Analyst required

Information/Analyst role - Experience of statistical techniques - Significant experience working on Data Analysis or statistics - NHS or Health ...

Earn 40,000 as a Statistician in Liverpool, North West apply now!

For the role you will need an MSc or PhD in either: Applied Statistics, Chemometrics, Mathematics, Operational Research or other numerate discipline ...

Infrastructure Project Manager with a Global Investment Bank in London

As an experienced Project Manager you will have a technical background in the Unix/Linux space and preferably significant exposure to the Market ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment