MSN Messenger spreads worm, not love

A worm that first disguised itself as an e-mail from computer vendors now attempts to trick MSN Messenger users into executing malicious files.

The Chod.B worm, which was first discovered on April Fools' day, spreads via e-mail purportedly from Microsoft, and security vendors Symantec and Trend Micro.

When using MSN Messenger as its propagation tool, the virus sends out messages to contacts from the infected user's address book, warning them that they are about to receive a file. The virus then sends a file designed to infect the recipient.

Trend Micro's senior systems engineer Adam Biviano said the development is 'alarming' because it mimics the behaviour of a real IM user.

"The virus will send you a message first saying 'check out what I just found on the Internet', and then send you [the malicious] file. It is not just sending files out of the blue anymore -- it is trying to imitate what a friend in your contact list would do," said Biviano.

Chod.B also contains a tool that allows it to steal passwords from a number of IM applications - including AOL, ICQ Lite, Miranda, MSN Messenger, Trillian, and Yahoo Messenger.

Biviano said that because the virus author has also included a way to communicate with the virus, it could mean that in the future the same virus could be instructed to infect more than just MSN Messenger users.

However, even when using e-mail to spread, Chod.B spoofs the 'from' field of the e-mail so it appears to have been sent from either security@microsoft.com, security@trendmicro.com or securityresponse@symantec.com.

According to Biviano, viruses in the past have tried to look like they were sent by Microsoft but this is the first time virus writers have tried to pass off a virus as a message from an antivirus company.

"We have seen them in the past from Microsft.com but not specifically from the other two addresses. It is just another social engineering attempt to try and trick users into executing the files," said Biviano.

Biviano said although Chod.B is cleverly designed, it is unlikely to become a widespread threat.

MSN Messenger -- which has previously been targeted by virus writers -- isn't the only instant messaging service to be exploited. Last week, phishers took aim at Yahoo's Messenger service by attempting to steal usernames, passwords and other personal information. The search giant admitted that attackers were sending its users links to fake Web sites that mimicked a Yahoo site and asked the user to log in by entering their username and password.

In fact, security firm Websense has warned that hackers are increasingly using instant messaging applications to fool users into installing malicious code and revealing personal information.

Advertisement

Talkback 6 comments

    hi its not realy a comment but ...Anonymous -- 25/04/05

    hi its not realy a comment but i think ive affected by this worms and i was wonder if you know how get rid of it

    ahh umm how do u get that off ...Anonymous -- 28/04/05

    ahh umm how do u get that off your msn becouse its ****ing me off every 5 mintues it sends it

    msn virus Anonymous -- 04/09/05

    please help me i was msn and was bored so i decied to click on a message wat had said hey, look at this: http://vbulettin.com/msn.php?email=rabbit_richard@hotmail.com and i downloaded it now ive got a virus and i cant sign into msn

    msn virus Anonymous -- 04/09/05

    please help me i was msn and was bored so i decied to click on a message wat had said hey, look at this: http://vbulettin.com/msn.php?email=rabbit_richard@hotmail.com and i downloaded it now ive got a virus and i cant sign into msn

    help me Anonymous -- 18/06/06

    i downloaded an msn add on that lets me imitate other ppl, but suddenly millions of pop ups with the letter "s" appear, what should i do?

    help me Anonymous -- 18/06/06

    i downloaded an msn add on that lets me imitate other ppl, but suddenly millions of pop ups with the letter "s" appear, what should i do?

Add your opinion

Latest Videos

Blogs

  • Darren Greenwood Telecom NZ savings damage prospects
    If Telecom NZ wants to have any of the NZ$1.5 billion the government intends to spend on its new broadband network, it had better think long and hard before offshoring 1500 jobs.
  • Array iiNet: The whys and what nows
    Last week the Federal Court ruled that internet service providers are not responsible for copyright violation by their customers. This is an important decision not just for iiNet, which spent around $4 million defending the case, but for all ISPs in Australia and, indeed, globally.
  • Array Govt, hurry up with releasing data
    A programmer scraped data from the My School website to make some really cool heat maps showing regions of smart schools — no thanks to the government, which didn't supply the data in any useful kind of format.
  • More blogs »

Tags

Back to top

Featured