Feeds

Santa worm is coming to IM

Someone's been naughty. Very, very naughty

Choosing a cloud hosting partner with confidence

A new virus is taking advantage of the Christmas-time custom of sending cards and joke attachments to spread itself among users of instant messenger software.

The IM.GiftCom.All, or Santa Claus worm presents itself as a harmless image of Santa Claus and appears to be sent from someone known to the recipient. If victims click the file a worm is loaded on to their computer. The worm then sends the same message to everybody on that person's address list.

The virus is part of a growing pattern whereby instant messaging programme users are being targeted by the writers of malware. The Santa Claus virus is just the latest instant messaging virus to be making the rounds, targeting the chat programmes provided by AOL, Microsoft and Yahoo. The worm was identified by IMLogic, which develops enterprise instant messaging software.

"There isn't huge awareness surrounding the risks of instant messaging viruses," Eamonn Phelan, senior consultant at Topsec Technologies told ElectricNews.net. "People need to ensure that their firewall is on and that their anti-virus software up to date."

Such worms are less successful than ones sent via e-mail, since they can only be delivered successfully if the recipient is logged on when the virus is sent. This is in contrast to an e-mail virus, where the malware can be activated at a later point when the victim logs on. In both cases the virus is only activated if the recipient chose to click on the link Home users are more vulnerable than corporate users, because most companies prevent their employees from using instant messaging software. Network administrators block chat programmes to prevent employees from getting distracted from their work, as much as to block viruses.

Santa's name is also being invoked by spammers selling fake luxury watches. These unsolicited e-mail messages contain a detailed recipe, including ingredients and instructions, on how to make "Santa's Chocolate Sleigh Bell Cookies". The spammers also provide a link to their website, which then offers to sell the fake watches.

Copyright © 2005, ENN

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
prev story

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.