Report: IM Attacks Hit Record Levels

By Ed Oswald | Published October 3, 2005, 4:10 PM

Instant messaging security firm IMLogic said on Monday that attacks on IM networks increased to record levels, multiplying by fourteen times through the first three quarters of this year.

"Over the past three months the nature of the IM threat has continued to evolve with increasing levels of sophistication and rates of infection demonstrated by IM worms and viruses," IMlogic CTO Jon Sakoda said.

The report concluded that MSN Messenger has been the recipient of the lion's share of attacks, accounting for 62 percent of reported incidents. 31 percent targeted the AIM client, and another seven percent were aimed at Yahoo! Messenger users.

By type of attack, 87 percent were worm-based, 12 percent hijacked file transfer to deliver viruses, and one percent utilized system vulnerabilities. Altogether, 713 different threats have been reported for IM and P2P applications.

IMLogic cautioned users of AIM and Yahoo from becoming complacent simply because MSN is the target of most attacks.

"While the majority of IM threat outbreaks continue to occur on a single network, during the third quarter of 2005 IM virus writers and hackers continue to increase the sophistication of their attacks," the report says.

Comments

I never got one of those IM's, but my brother did (he's at college, go figure).

But he was smart enough to not click it, hell, he doesnt even trust his own brother, when i give him a link.

Score: 0

|

hmmm... A company that makes money by securing IM says... "IM attacks are on the rise."

FUD Rules.

Score: 0

|

Sad to know Winmx is gone!, but why don't programmers create a mp3's converter, made to look like a Data File, not the mp3 or wav?~then it should be legel LOL.
If it looks like a data file, what can they do to you, I know they can't stop us from downloading files NOW, the heck with them, the RIAA don't own the interent, nor does the government the users the world, its free, this mp3 converted to a data; Now when its sent through your modem, via your ISP, it will have to be converted on the other end - with the same program -convert to mp3, who's to be the wiser
, oops of course this stuff must be underground software. Like those those underground
Drug clubs. ANyway, I heard that the same company, RIAA? can get a copy of Files ever downloaded from you download from your ISP, and who did it; then convict you if you download/uploaded anything like mp3, mpegs ect....

Hope bothside comes to a good outcome!

Score: 0

|

downloader didnt u post this in the wrong section by mistake. but hehehe ur idea is sure a great idea .. ;)

Talking abt IM attack, can any IM be safe ? I mean if you will fully download a file and then run it without knowing what you are doing do you really have any right to use internet at all or am I undestanding something absolutely wrong :-/.

Score: 0

|

Opps I was in Winmx, then I saw MSN IM attacks, and clicked on the link to read about that news, and jumped here, I thought when you post a comment It was one board, all about winmx :S I am new in Betanews, I think that when we use winmx, msn IM to download its free, nomatter where you live. But if someone don't start doing something now, the courts will make it totally Illegal to download anything, other then HTML files ASP JPG ect. even if I convert my songs then it will really look like trash letters in the file, so how can they touch us when they can't prove it lol. One day I went to my radio station online to listen to whats playing, they took it off the interent because of what was happening to Napster, they resumed live Internet at my favorite Radio station. So they issue is effecting how we do internet these days, I just wish we could all stand strong and win the battle, before we can't even do Private P2P file trasfereing yahoo msn, or just a program you made using Visual Basic, I programmed in Visual Basic 6 many P2P file Transfer back then.
BUt if I ever started again I would Convert my MP3 and even the Filename so I don't get in trouble for Sharing!. Hope to see both sides Solve there problems

Score: 0

|

I see more on AIM than the others, but I know MSN has had its fair share in the past, and Yahoo as well.

Here at the college I work the students just had a big outbreak of the most recent AIM bug... it's been causing everything from blue screens to random freezes.

Score: 0

|

Yup. Same here. And all the friends I got the virus link from are at other colleges. I thought that was a little strange...

Score: 0

|

These are definitely not new attacks. Every time I hear of any attack, I'm glad that I use Linux because I know that nothing will happen to me even if I (or some guest using my computer) is stupid enough to click them.

Score: 0

|

See worms fairly regularly on the MSN network, but haven't seen one on ICQ yet. I use the Miranda client - I usually notify the infected invidual straight away that they're sending dodgy links to all their contacts.

Score: 0

|

"attacks on IM networks increased to record levels, multiplying by fourteen times"
Anyone up for some math?
ok lets do it :
1x14=14 (that looks about right)
ok guys id say there was 14 attacks up to now...better watch out.

Score: 0

|

Unless of course the initial number of attacks was like 100,000. Then you're math would be:
100,000 x 14 = 1,400,000. :)

Score: 0

|

The only attack i got was, HeartBurn. reading this!!

Score: 0

|

They're not actually attacks, just messages with .php links. They normally come from people who have you on their buddy list, without their knowledge of sending the message. The major problem with the latest string is that users don't know they're infected. If you use firefox, then the infected links have no effect. It's actually kind of entertaining to watch it spread.

Score: 0

|

In the last 6 years of using AIM, Yahoo, ICQ, and MSN I have never seen or experienced an attack.

I don't use Trillian or GAIM, I use the real clients.

I used to use ICQ and AIM all the time but now I use Yahoo and MSN.

Never one attack.

Score: 0

|

Probably because you're (going out on an assumption here) not a complete idiot that clicks on every link and file your contacts send you without first finding out what they're sending and why.

Score: 0

|

Any readers of BetaNews ever experienced one of these attacks? Or even an attempted attack? I never have, but am interested to find out more.

Score: 0

|

I got the link from three different friends.

They all sent me the exact same message, which was something like... ...wait a minute, I have it in my logs...

Here you go (link changed so people don't click it):

"LOL LOOK http://www.somevirussite.net/pictures.pif !!!"

I didn't click it because I knew it was bad, and I told all my friends about it, which now have an UPDATED AV client on their computers.

**EDIT**
All of those links came from friends on AIM, although I do use all the major ones 24/7.

Score: 0

|

One can be tricked, because it can appear as your closest friends are sending you a file.

Perhaps this is an illustration. Say you have a friend whom you swap files with regularly through a messenger(myself and my friends are programmers, so executables are more than ordinary).

It can be easy to slip up and grab something by accident, especially since alot of the new attacks use bot ai to give it a more human approach to getting you to download it(seeming real enough for the seconds beforehand hand).

Yes, I'm ashamed to say I caught a worm once, but at the time I wasn't aware of worms travelling through instant messengers(this was a few years ago). To make matters worse, it send itself to all my people on my list without me knowing it, and screwed them up to. I spent the time undoing the worm's damage on my own computer as well as friends' and family's computers.

Score: 0

|

Lol! Yeah, it's always tempting to click on links just out curiosity I guess.

See a link, click on it, got a worm!

Score: 0

|

Weird. through all the press I've never seen one. Guess only accepting from people you know would be a good start. oh well, to each their own, darwin in action.

Score: 0

|

and according to my statistics, it has decreased dramatically over the last 2 years.

Score: 0

|

The only IM attacks I recieved are messages from my ex girlfriend.

Score: 0

|

LOL

Score: 0

|

LMAO!

Score: 0

|

hmm ok?

Score: 0

|

My friends got a BlockChecker virus it sends a message to all her contacts every time she talks to them and she cant see it if you download the program from the link it gives you the same virus she didnt realise she had it for ages.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET