eWeek Security Watch
Advertisement
Advertisement
August 28, 2009 12:23 PM

Symantec: Eavesdropping Trojan Targets Skype



Who needs a digital voice recorder when you have malware?

According to Symantec
, source code for a new Trojan targeting users of Skype VOIP has appeared on the Internet.

So far there is no evidence the malware is spreading, but with the source code now public, it is possible malware writers can begin leveraging this type of functionality.

The Trojan injects a thread into the Skype process and hooks a number of Windows API calls, enabling it to eavesdrop on conversations before they reach Skype or any other audio application. After recording the audio, the malware can store it in an encrypted mp3 file and send it out to a predefined server where the attacker can access the conversations.

By recording the call as an mp3, the size of the audio file is kept low, which in turns make the process of transferring the data over the network faster.

"Skype has simply become a victim of its own popularity, most likely being targeted simply because it has such a large install base," according to Symantec Security Response. "This threat could just have easily been crafted to take advantage of any one of the myriad of other VOIP applications, and it's likely we'll see other threats in the future that do just that."

Symantec warns that with a little social engineering, an attacker could trick a user into downloading the Trojan, which is detected by Symantec as Trojan.Peskyspy.

At the moment however, the security vendor believes the risk posed by the threat is relatively low at this time.

"What we've seen is largely proof-of-concept and does not contain any method to spread from one computer to another," according to the blog. "However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date."

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/17763

Comments (2)

Philbrook Sargent :

I did a search for "trojan" and did not find any. However, I have received several invitation for unknown persons to join my buddy list on Skype. All my prefs are set to be viewed only by those on my buddy list. So, something is amiss with the Skype security.

I discovered to my absolute amazement that SKYPE keeps my credit card information on a live file.
Vendors keeping credit card information of their customers is one of the vulnerabilities that has been exploited by thieves. Why do they do this? It should be prohibited. In my own case I made the discovery because I changed my credit card number ((everyone should do this from time to time)) and received an eMail from SKYPE complaining that they could not access my credit card account!!
As a Canadian I am protected by strict federal privacy laws. Recently my Government cracked down on Facebook. I am going to file a formal complaint against SKYPE this week, and as a former Canadian Government official, I am pretty certain the hammer will come down on SKYPE.

Post a Comment

 
 
RSS Syndication
Advertisement

CAG

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise