ICQ Worm Spreads Malicious Payload Before Being Blocked

By Matthew Hicks  |  Posted 2004-02-25 Print this article Print

AOL has blocked the Bizex worm that began spreading through the ICQ instant messaging service this week, carrying with it the ability to steal sensitive information

America Online Inc. said it has blocked a worm that began spreading this week through its ICQ instant messaging service that can steal sensitive information from infected machines. The worm, named Bizex, began spreading among ICQ users on Tuesday, and preliminary reports identified more than 50,000 infected machines worldwide, according to a security alert from Kaspersky Labs Int. The worm, which makes use of breaches in Microsoft Windows and Internet Explorer, spreads by sending an instant message to ICQ users that includes a link to the www.jokeworld.biz Web site. When a user visits the site, it shows what appears to be an innocuous cartoon but in the background replicates the worm onto the users machine.
AOL, in a message posted on Wednesday to ICQ users, said that it had blocked further distribution of the worm on its ICQ servers. The Dulles, Va.-based company also said that the worm only affected "a small number" of users of the ICQ Pro instant messaging client, and not users of other ICQ clients such as ICQ Lite. An AOL spokeswoman declined to specify the number of infected users.
On infected machines, the worm disconnects the ICQ client and accesses the ICQ contact list in order to send IMs, appearing to be from the infected user, to other ICQ members, Kaspersky reported. AOL, in its posting, stated that it is working on a fix for infected ICQ Pro users who can no longer use the IM service. More troublesome is the worms malicious payload. The worm can steal sensitive information from financial services transactions and e-mail accounts. It can scan the infected computer and gather information on payment systems, sending the details to a remote server, Kaspersky said. In addition, Bizex can intercept information transmitted by HTTPS and log-in information for popular e-mail services. Bizex joins a growing list of worms propagated through IM services. AOL Instant Messenger in February was the target of a worm that spread as a game about Osama bin Laden but also downloaded ad software called Buddylinks. MSN Messenger in December faced a worm called Jitux, which also spread when users clicked on a link sent through IM. Bizex, though, marks an escalation in the ferocity of the worm attacks because of its malicious payload and demonstrates the increasing danger of IM viruses and worms, said Dmitry Shapiro, chief technology officer and founder of Akonix Systems Inc., an IM management and security vendor. A big part of the problem, he said, is that corporations have left IM unmanaged and insecure on their networks. "Its becoming too tough to get a virus to propagate over e-mail, but on IM theres this new frontier where its easy to make this work," Shapiro said. "Virus and worm writers will start using instant messaging as a primary mode of propagation." Check out eWEEK.coms Messaging Center at http://messaging.eweek.com for more on IM and other collaboration technologies.
Matthew Hicks As an online reporter for eWEEK.com, Matt Hicks covers the fast-changing developments in Internet technologies. His coverage includes the growing field of Web conferencing software and services. With eight years as a business and technology journalist, Matt has gained insight into the market strategies of IT vendors as well as the needs of enterprise IT managers. He joined Ziff Davis in 1999 as a staff writer for the former Strategies section of eWEEK, where he wrote in-depth features about corporate strategies for e-business and enterprise software. In 2002, he moved to the News department at the magazine as a senior writer specializing in coverage of database software and enterprise networking. Later that year Matt started a yearlong fellowship in Washington, DC, after being awarded an American Political Science Association Congressional Fellowship for Journalist. As a fellow, he spent nine months working on policy issues, including technology policy, in for a Member of the U.S. House of Representatives. He rejoined Ziff Davis in August 2003 as a reporter dedicated to online coverage for eWEEK.com. Along with Web conferencing, he follows search engines, Web browsers, speech technology and the Internet domain-naming system.

Submit a Comment

Loading Comments...
Manage your Newsletters: Login   Register My Newsletters

Rocket Fuel