Trojan attacks - Symantec: Eavesdropping Trojan Targets Skype - eWeek Security Watch

Symantec: Eavesdropping Trojan Targets Skype

Written By
Brian Prince
Brian Prince
Aug 28, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Who needs a digital voice recorder when you have malware?

According to Symantec, source code for a new Trojan targeting users of Skype VOIP has appeared on the Internet.

So far there is no evidence the malware is spreading, but with the source code now public, it is possible malware writers can begin leveraging this type of functionality.

The Trojan injects a thread into the Skype process and hooks a number of Windows API calls, enabling it to eavesdrop on conversations before they reach Skype or any other audio application. After recording the audio, the malware can store it in an encrypted mp3 file and send it out to a predefined server where the attacker can access the conversations.

By recording the call as an mp3, the size of the audio file is kept low, which in turns make the process of transferring the data over the network faster.

“Skype has simply become a victim of its own popularity, most likely being targeted simply because it has such a large install base,” according to Symantec Security Response. “This threat could just have easily been crafted to take advantage of any one of the myriad of other VOIP applications, and it’s likely we’ll see other threats in the future that do just that.”

Symantec warns that with a little social engineering, an attacker could trick a user into downloading the Trojan, which is detected by Symantec as Trojan.Peskyspy.

At the moment however, the security vendor believes the risk posed by the threat is relatively low at this time.

“What we’ve seen is largely proof-of-concept and does not contain any method to spread from one computer to another,” according to the blog. “However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.