Daily cyber threats and internet security news: network security, online safety and latest security alerts
May 7th, 2010

Advanced Social Engineering Worm Infects Yahoo! Messenger And Skype Users

Security researchers warn that a new worm is targeting instant messaging users. Spotted on Yahoo! Messenger (YM) and Skype, the attacks use sophisticated social engineering techniques to trick users into infecting themselves.

It certainly looks like IM worms are making a comeback on the threat landscape, as this is the second malware of this kind to emerge in under a week. Just this Monday, the online community was abuzz with news of a worm rapidly spreading through Yahoo! Messenger. The threat was so serious that BitDefender saw fit to release a standalone removal tool.

Security researchers from Vietnamese antivirus vendor Bkis are again amongst the first to report on the new attacks, which, this time, have extended beyond YM and affect Skype too. “Still using the method of inserting malicious URLs into chat windows like [their alias for the worm discovered earlier this week], however, social engineering skill of the Worm, this time, is much more sophisticated than the previous one,” they warn.

The messages used to lure potential victims are more enticing and variate with each attack. “Does my new hair style look good? bad? Perfect? ;)” or “My printer is about to be thrown through a window if this pic won’t come our right. You see anything wrong with it?” are just two examples. Also, the spammed image URLs end in actual .JPG and point to a RapidShare lookalike website called

Hitting the download button on the page prompts the download of an archive file called Inside the archive, there is a .COM MS-DOS executable file deceptively called, which installs a variant of a backdoor named Tofsee, Flot or Skyhoo, depending on antivirus vendor.

Bkis points out that while Skyhoo installs an IRC botnet client, just as Ymfocard, the new worm is much more complex. For one, it is able to block antivirus software from functioning properly and uses a rootkit component to hide itself. Moreover, it also adds malicious links to any Word and Excel document opened on the computer or any email composed in Outlook. It also infects removable USB drives and creates an autorun.inf file to execute itself.

YM and Skype users are advised to exercise increased caution when choosing to open links received from their friends and, as always, connect to the Internet with a capable and up-to-date antivirus product installed. At the time of writing this article, only 13 out of 41 AV engines on VirusTotal detect the .COM file as being infected.

Credit: News

Share this item with others:

More on CyberInsecure:
  • Yahoo! Messenger Users Infected By New Worm, Form An IRC Botnet
  • Skype Encrypted Instant Messages Can Be Eavesdropped
  • Unpatched Yahoo! Messenger Flaw Allows Status Updates Remote Hijacking
  • Skype File URI Security Bypass Code Execution Vulnerability
  • Computer Worm Infects International Space Station Laptops

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Advanced Social Engineering Worm Infects Yahoo! Messenger And Skype Users

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.