New worm spreading via ICQ

Boscoh

Senior member
Jan 23, 2002
501
0
0
This is a first. There's a new worm out there that is spreading via ICQ. It directs you to a link, where one of the IE and Windows exploits is used to drop a worm onto your system which then does some of the following things:

1) Collects financial data specific to a few sites (ie Wells Fargo, ETRADE, AMEX, VeriSign, among others).

2) Installs a key logger to log keystrokes made when connected via HTTPS (which is what a lot of financial sites use when you view your account info).

3) Sends the link out to everyone on your ICQ list.

It sends the info collected in steps 1 and 2 to a server somewhere.

Scary stuff for sure. Here's the link to some techweb info.

http://www.techweb.com/wire/story/TWB20040224S0006

And Kaspersky labs info:

http://www.viruslist.com/eng/viruslist.html?id=1029528

The worm is called Bizex.

EDIT: AOL has said they have blocked the worm from spreading through their ICQ servers. Take that for what it's worth. But heres info on it:

http://www.eweek.com/article2/0,4149,1539086,00.asp
 

Boscoh

Senior member
Jan 23, 2002
501
0
0
I dont use it often, but yes, I still use it.

I posted this mainly because it's interesting. I figured quite a few people who read this forum still use it, so they might want to know. I also think that more and more viruses are going to start propagating via IM. Simply because people are not used to having to worry about viruses coming through their IM program, and because so many companies let employees use seriously insecure IM programs on their networks. They focus so much on email, that it is a lot harder to get a virus to spread via email now that it was when...say...Nimda was released. Not many people focus on IM too much.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Evidently enough people still use ICQ, because this got raised from Low to Medium threat level in McAfee's view, for both home and corporate users. That struck me as strange, at least for corporate users (corporate users running ICQ? :confused: ). Anyway, get yer virus-defintion updates folks.