On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matt Hines
Posted on ZDNet News: Mar 8, 2005 6:23:00 PM

New worms that use Microsoft's instant-messaging software to spread are tunneling their way across the Web.

Antivirus companies on Tuesday flagged a variation of an existing threat and a new worm, both targeting MSN Messenger.

Researchers at both Aladdin Knowledge Systems and F-Secure discovered the appearance of Win32.Kelvir.a, a new twist on the previously identified Kelvir threat. Each company also identified a new worm in the wild; Aladdin is calling it Win32.Serflog.a., while F-Secure is calling the same threat Sumom. Aladdin is rating both Win32.Kelvir.a and Win32.Serflog.a as medium-to-high risks.

"Most people still do not expect to get viruses via IM...(It's) a new way to bypass existing security methods and get into PCs."
--Shimon Gruper,
vice president of technology,
Aladdin Knowledge Systems

The appearance of the new worms underscores the growing popularity of malicious software that relies on instant messaging, or IM, to spread. It follows a similar attack last month by another program meant to use Messenger to spread itself. In early February, researchers at Trend Micro detailed a variant of the Bropia worm that used Messenger. The Bropia.f worm was packaged with a second, more damaging worm that tried to exploit computers with improperly patched software.

While Microsoft spokesmen were quick to point out that the Messenger attacks do not take advantage of any flaw in the software, the company said it recommends that customers exercise "extreme caution" when accepting file transfers from both known and unknown sources on IM.

According to Aladdin, Win32.Kelvir.a spreads via a URL sent in an IM that contains an infected file. After clicking on the link, a person's computer becomes infected by the worm. When the program is executed it attempts to drop multiple copies of itself onto the person's PC. The worm also executes itself with every subsequent startup of the IM software by modifying registry entries, and it forwards itself to all of an individual's IM contacts. The threat presents itself hidden in a message that reads "omg this is funny!", followed by the URL.

Aladdin said that Win32.Serflog.a, or Sumom, presents itself as an attachment in an instant message. The worm attempts to spread by dropping copies of itself into folders typically shared by peer-to-peer software clients. The infected message reads "????omg click this!", followed by an attachment that harbors the worm. The company said Win32.Serflog.a also drops several hidden files into infected machines and attempts to cancel security functions of Messenger, while blocking access to several related Web sites.

In the first six weeks of 2005, 10 instant-messaging worms and their variants spread over America Online, ICQ and MSN networks, according to researchers at Akonix Systems. That's more than three times the number of worms that spread over public IM networks over the same period last year, and Akonix expects the trend to continue to climb.

Shimon Gruper, vice president of technology at Aladdin, said that the Kelvir variant probably poses a greater risk to IM users, because people are far more likely to click on a Web link than they might be to open an attachment. However, because both of the worms are designed to appear as if they've been sent by a known contact, he believes that either could do serious damage.

"Most people still do not expect to get viruses via IM," Gruper said. "They know about viruses sent in e-mail, but they're not as informed about IM threats, which pop up on your desktop and look like they come from someone you already talk to. IM worms are a growing threat because the hackers have tried to exploit almost every opening they can find in e-mail software, and IM is a new way to bypass existing security methods and get into PCs."

The latest round of worms targeting Messenger also bear some signs that the individuals writing the malicious programs have begun to use the threats to communicate with one another, possibly in a manner similar to street gangs' use of graffiti tags to mark their territory. A text file deposited on infected machines by Win32.Serflog.a features a message to "Larissa," the name for the hacker thought to be responsible for a worm known as Assiral.a, which attempted to disable the malicious Bropia worm.

Munir Kotadia of ZDNet Australia contributed to this report from Sydney.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 67 Talkback(s)
speechless...
i was trying to think of something to say here, but i cant believe how this guy can allow his computer to become infected (evedently without running adaware, spybot and avg at minimum) and expect it is the banks fault. why not sue m$? i mean damn! holy schnikes. wow.... (Read the rest)
Posted by: linuxoverwindows Posted on: 03/09/05 You are currently: a Guest | | Terms of Use
Kopete  Linux User 147560 | 03/08/05
Correct me if I'm wrong  NonZealot | 03/08/05
As for your last paragraph  FilledOut | 03/08/05
OK, I'll correct you..  Jeff Spicoli | 03/08/05
Your computer makes a pretty paperweight  NonZealot | 03/08/05
Actually..  Jeff Spicoli | 03/08/05
SRP  Real World | 03/09/05
besides...  linuxoverwindows | 03/09/05
They can run executables  Michael Kelly | 03/08/05
Which ones though?  Jeff Spicoli | 03/08/05
I wouldn't call defrag "simple"  Michael Kelly | 03/08/05
I run as..  Jeff Spicoli | 03/08/05
Re: I run as..  PA-ITGuy | 03/08/05
RE: runas  linuxoverwindows | 03/09/05
Re: Re: run as  NonZealot | 03/09/05
Re; RE: runas  PA-ITGuy | 03/09/05
re: runas - selinux  linuxoverwindows | 03/09/05
It's all about file and registry permissions  toadlife | 03/08/05
Good post  Real World | 03/09/05
They Might be able to  osreinstall | 03/08/05
neh?  linuxoverwindows | 03/09/05
You are correct  Michael Kelly | 03/08/05
You may be right, I may be crazy...  The King's Servant | 03/08/05
rm -rf /  linuxoverwindows | 03/09/05
First socially engineered Linux worm!  NonZealot | 03/09/05
oh, dang  linuxoverwindows | 03/09/05
Although that is useful info...  IT Scion | 03/08/05
Message has been deleted.  Jeff Spicoli | 03/08/05
(nt)I use Trillian for Windows  toadlife | 03/08/05
you can also  jdahs@... | 03/08/05
but its blue and underlined...  linuxoverwindows | 03/09/05
It is not IM  michael-t | 03/08/05
even after a FORCED update, still getting VIRUSES!  matrixdomain | 03/08/05
Did this FORCED update cost money  The King's Servant | 03/08/05
You bite the ...  ShadeTree | 03/08/05
"Proffessional" Geek, not "Vocational" Geek. wink  The King's Servant | 03/08/05
I declare shenanigans!!  Real World | 03/09/05
ive played scrabble but not shenanigans  linuxoverwindows | 03/09/05
Eighter way M$ is so flawed and insecure  matrixdomain | 03/08/05
Let me guess...  toadlife | 03/08/05
Troll  NonZealot | 03/08/05
On that note  toadlife | 03/08/05
I did notice..  Jeff Spicoli | 03/08/05
I think I'm being chased...  The King's Servant | 03/08/05
I'm a proud and virus free Linux user  matrixdomain | 03/08/05
Mike Jr.?  toadlife | 03/09/05
don't have technical discussion?  matrixdomain | 03/09/05
RE: matrixdomain  ShadeTree | 03/09/05
Re: I'm a proud and virus free linux user  matrixdomain | 03/09/05
RE: Matrix Domain  ShadeTree | 03/09/05
there are NO Virus worries in Linux  matrixdomain | 03/09/05
RE: matrixdomain  linuxoverwindows | 03/09/05
RE: don't have technical discussion?  toadlife | 03/09/05
Re: technical discussion  matrixdomain | 03/09/05
Sure thing buddy.  toadlife | 03/09/05
RE: matrixdomain  ShadeTree | 03/09/05
I use windows and am virus free  JasonL31 | 03/09/05
are you sure you don't have a windows virus?  matrixdomain | 03/09/05
Preaching to the choir (didn't you read my full disclosure?)  The King's Servant | 03/08/05
wineX or cedega  linuxoverwindows | 03/09/05
forced update?  linuxoverwindows | 03/09/05
Microsoft takes security-patch hiatus...  Rick_K | 03/08/05
Calling all MS-Trolls. Don't mention "Istanbul"  whisperycat | 03/09/05
who in thier right mind would use msn - lol  JasonL31 | 03/09/05
my right mind  linuxoverwindows | 03/09/05
Here's how much Windows Viruses will cost you  matrixdomain | 03/09/05
speechless...  linuxoverwindows | 03/09/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here