Trojan horse
Mutant version of IRCbot is disguised as the latest Skype release

Skype spoof hides IRCbot Trojan

Nasty sting in the tail for users of popular VoIP client

Written by Robert Jaques

Security experts today warned of a newly discovered mutant version of the IRCbot (aka Fanbot) Trojan, which is being distributed via email disguised as the latest release of the popular Skype VoIP software client.

MessageLabs said that it has intercepted more than 800 copies of the mutant Trojan, which purports to be version 1.4 of Skype's client software released last week.

When executed the malware displays a fake 'installation error' box while installing itself as '%sysdir%\remote.exe', altering the registry and shutting down shared access and Windows update services.

It then tries, but fails, to connect to either an IRC server named 'jojogirl.3322.org' (channel name #Phantom) or 'smallphantom.meibu.com'.

"This latest 'spear' phishing attack, where Skype users are being targeted with an email that appears to come from Skype, is the first case we've seen that specifically mentions Skype," said Maksym Schipka, a senior antivirus researcher at MessageLabs.

"It is another clear example of how malware writers are quickly exploiting newly identified security holes, as we saw with the Zotob attack, and now with releases of popular software applications in order to try and spread their malicious payloads."

The Trojan typically arrives in an email with the following subject line:

'Hello. We're Skype and we've got something we would like to share with...; Share Skype.; Skype for Windows 1.4; Skype for Windows 1.4 - Have you got the new Skype?; What is Skype?'

The body text of the bogus email is as follows:

Dear user,
Skype is a little piece of software that lets you talk over the Internet to anyone, anywhere for free. And it just got even better -- download the latest version of Skype: Our call quality is the best ever for talking, laughing and sharing stories. You can forward calls on to mobiles, landlines and other Skype Names. Make calls instantly from Outlook email or Internet Explorer with our new toolbars. Personalise your Skype -- play around with sounds, ringtones and pictures to show the world who you are.
For further details see the attached document.
This message contains graphics. If you do not see the graphics, click here to view. (c) 2002-2005 by Skype Technologies S.A. Legal information.

Tags:

Further reading

Related articles

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers   More...

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market   More...

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Homer Simpson spreading malware

Web 2.d'oh!   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement