New IM worm targets Skype users

A new instant-messaging pest that spreads using the chat feature in Skype has surfaced, security firm F-Secure warned Monday.

The worm, dubbed Pykse.A, is similar to threats that affect instant-messaging applications. A targeted Skype user will receive a chat message with text and a Web link that looks like it goes to a JPEG file on a Web site, F-Secure said on its Web site.

Clicking the link will redirect the user to a malicious file. The file, after executing, will send a malicious link to all online contacts in a Skype user's list and will show a picture of a scantily clad woman, F-Secure said. In addition, it sets the user's Skype status message to "Do Not Disturb," the security firm said.

Pykse also visits a number of Web sites that don't host any malicious code and a site that appears to count infected machines, F-Secure said. The Finnish security company doesn't list any particular malicious payload for Pykse other than it spreading and visiting Web sites. The IM worm affects Skype users running Windows.

Such threats for Skype aren't new. Last month, miscreants adapted the Warezov Trojan horse to target Skype users. This threat also arrived with a Web link sent in a Skype chat message. Clicking on the link would result in a PC being at the beck and call of the attacker and the Trojan horse sending messages to the victim's Skype contacts.

In February, attackers also targeted Skype users with another Trojan horse that had propagation capabilities.

Skype has acknowledged in the past that its instant-messaging feature could be used for nefarious purposes just like any other IM service. Kurt Sauer, Skype's chief security officer, repeated that acknowledgment on Monday in a statement sent by the company's public relations agency.

"Harmful viruses and Trojan horses may damage a user's computer and collect private data, regardless of whether a person is using Skype, e-mail or other IM clients," Sauer said in the statement. "Skype strongly recommends that users take extra caution in general when asked to open attachments or links from unknown people, or suspicious-looking attachments even from people you know."

Skype also recommends using antivirus software to check the files received from other people.

More from News.com on this story's topics

Security threats

Create an email alert | RSS feed

Viruses and worms

Create an email alert | RSS feed

Security

Create an email alert | RSS feed

eBay

Create an email alert | RSS feed

See more CNET content tagged:
Skype, Kurt Sauer, F-Secure Corp., IM, worm

Add a Comment (Log in or register) 6 comments (Page 1 of 1)
Does this affect ALL Skype users or just PC Skype users?
by Macsaresafer April 16, 2007 3:45 PM PDT
Judging by the name, I'm guessing it only infects Windows users of Skype. http://www.f-secure.com/v-descs/im-worm_w32_pykse_a.shtml
Reply to this comment
Just to be picky,
by Marcus Westrup April 16, 2007 3:59 PM PDT
A "Trojan horse that had propagation capabilities", is more properly called a Worm (with multiple infection vectors). 8-)
Reply to this comment
Again, no list of affected OS's.
by evan1138 April 16, 2007 4:19 PM PDT
There is no mention of which operating systems are susceptible to this malware, and this is a serious disservice to your readers. Take our case: After 15 years, we are spending a good deal of money switching our business entirely to Intel Mac's, primarily for security reasons, though usability is also improved. We run a small number of PC-only programs (flawlessly) in virtual machines on our Macs at the same time as running OS X. The PC side of the Mac does not have email and is limited to only a few IP addresses on the net. We do not currently use any antivirus protection for the PC or the Mac sides. Incidentally, we do sophisticated software, firmware and hardware for robotics education and research. (No battle bots or hobby work products) and we have been dealing with the horrors or Microsoft internals for many years. Their operating systems are houses of cards, and they continue to be so because Microsoft's monopoly position (threatened by the Clinton administration but then predictably left virtually untouched by Bush) allows them to get away with it. Your news organization should not be part of this silence. It may be that reporters or news outlets are somehow being intimidated by Microsoft's legal clout so that no mention is made that these are windows problems. (At least I expect they are. Certainly, if these were OS X or Linux problems they would be generating a different kind of story altogether.) But whether the omission is from fear or laxity or some other source, it is a glaring omission all the same. I think you have to decide whether you are reporters or shills.
Reply to this comment
Don't Trust Your Friends
by Stating April 16, 2007 10:11 PM PDT
Sauer's advice about only trusting content from your friends doesn't hold water, because as the article states the worm sends the bad link to all the victim's contacts. You would think by now these guys would have a clue. This is the same crappy advice that Microsloth keeps dishing out. The advice should be, "Don't trust strangers and don't trust your friends. Better yet, don't use our crappy insecure product." "Clicking the link will redirect the user to a malicious file. The file, after executing, will send a malicious link to all online contacts in a Skype user's list..."
Reply to this comment
Windows Only
by telecommunicate April 17, 2007 12:46 AM PDT
From the F-Secure website, only "32-bit versions of Microsoft Windows" are affected. (This is what their "Platform: W32" designation means.)
Reply to this comment
Sure, let's believe F-secure
by Schratboy April 18, 2007 6:45 AM PDT
Each of these so-called security companies has a vested interest in reporting the next new Worm, Trojan or malicious exploit. A press release features their efforts and everyone is urged to update their security software. At the root of all this hype are basic security practices: Don't answer anything from a stranger, don't click on random chat links and don't buy into F-secure's hype.
Reply to this comment
Powered by Jive Software
advertisement
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.
Today's Top Stories
Yahoo tries to conceal lawsuit documents
Social graphs just wanna be free, but will they?
HP to launch fall line of teen-designed products
Conde Nast buys Ars Technica
Google to host 'Factory Tour' Monday morning
Most Popular Stories
Images: Microsoft telescope puts universe on your desktop
Photos: Cracking open the Atari 2600
This VC forecast scares the pants off of me
End of Intel, AMD duopoly near? Via readies Isaiah chip
Photos: Microsoft previews 2008 Xbox games
Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

Markets

Market news, charts, SEC filings, and more

Related quotes

eBay (-2.38%) -0.76 31.17
Dow Jones Industrials (-0.05%) -5.86 12,986.80
S&P 500 (0.13%) 1.78 1,425.35
NASDAQ (-0.19%) -4.88 2,528.85
CNET TECH (0.05%) 0.88 1,783.62
  Symbol Lookup
Detroit auto show
Detroit auto show

Detroit auto show
advertisement
On MovieTome: SEX AND THE CITY clips are here!
Advanced
search
Advanced
search
Visit other CNET Networks sites: