Symantec: Eavesdropping Trojan Targets Skype
Who needs a digital voice recorder when you have malware? So far there is no evidence the malware is spreading, but with the source code now public, it is possible malware writers can begin leveraging this type of functionality. The Trojan injects a thread into the Skype process and hooks a number of Windows API calls, enabling it to eavesdrop on conversations before they reach Skype or any other audio application. After recording the audio, the malware can store it in an encrypted mp3 file and send it out to a predefined server where the attacker can access the conversations. By recording the call as an mp3, the size of the audio file is kept low, which in turns make the process of transferring the data over the network faster. "Skype has simply become a victim of its own popularity, most likely being targeted simply because it has such a large install base," according to Symantec Security Response. "This threat could just have easily been crafted to take advantage of any one of the myriad of other VOIP applications, and it's likely we'll see other threats in the future that do just that." Symantec warns that with a little social engineering, an attacker could trick a user into downloading the Trojan, which is detected by Symantec as Trojan.Peskyspy. At the moment however, the security vendor believes the risk posed by the threat is relatively low at this time. "What we've seen is largely proof-of-concept and does not contain any method to spread from one computer to another," according to the blog. "However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date." |


Comments (2)
I did a search for "trojan" and did not find any. However, I have received several invitation for unknown persons to join my buddy list on Skype. All my prefs are set to be viewed only by those on my buddy list. So, something is amiss with the Skype security.
Posted by Philbrook Sargent | August 31, 2009 10:45 AM
I discovered to my absolute amazement that SKYPE keeps my credit card information on a live file.
Vendors keeping credit card information of their customers is one of the vulnerabilities that has been exploited by thieves. Why do they do this? It should be prohibited. In my own case I made the discovery because I changed my credit card number ((everyone should do this from time to time)) and received an eMail from SKYPE complaining that they could not access my credit card account!!
As a Canadian I am protected by strict federal privacy laws. Recently my Government cracked down on Facebook. I am going to file a formal complaint against SKYPE this week, and as a former Canadian Government official, I am pretty certain the hammer will come down on SKYPE.
Posted by Rockcliffe Park | September 1, 2009 8:54 AM