SAN FRANCISCO ? An April Fool?s Day worm that disguised itself as email from computer vendors is now attempting to trick MSN Messenger users into opening its malicious files, which can be used to steal passwords.
The Chod.B worm spreads through e-mail that supposedly comes from Microsoft and security companies Symantec and Trend Micro. When activated, the virus sends out messages to contracts in the infected user?s address book, warning them that they are about to receive a file. The virus then sends its bogus payload to the receipient.
Chod.B also contains a tool that allows it to steal passwords from a number of IM applications, including America Online’s AIM, ICQ Lite, Miranda, MSN Messenger, Trillian and Yahoo Messenger. Because the virus author has included a way to communicate with the virus, it could mean that in the future the same virus could be instructed to infect more than just MSN Messenger users, CNET.Com reported.
However, even when using e-mail to spread, Chod.B spoofs the “from” field of the e-mail so it appears to have been sent from either [email protected], [email protected] or [email protected].
MSN Messenger isn’t the only instant messaging service to be exploited. Last week, phishers took aim at Yahoo’s Messenger service by attempting to steal usernames, passwords and other personal information. The Internet giant confirmed that attackers were sending its consumers links to fake Web sites that mimicked a Yahoo site and asked the user to log in by entering their username and password.
Security company Websense has warned that hackers are increasingly using instant messaging applications to fool users into installing malicious code and revealing personal information.




