Original URL: http://www.theregister.co.uk/2008/01/23/polyglot_msn_worm/

Polyglot worm spreads over MSN

Mind your language

By John Leyden

Posted in Security, 23rd January 2008 23:15 GMT

A namedropping MSN Trojan is doing the rounds through MSN Messenger.

The IRCBOT-RB Trojan poses as messages containing links to pictures on social networking sites such as MySpace and Facebook. Typical come-ons involve messages such as "Wanna see my pictures before i send em to facebook?". Clicking on a link takes users to booby-trapped websites.

Unusually, the polyglot malware changes these messages according to the language of the affected operating system used. Compromised machines are infected by a simple bot agent that leaves the hardware hooked up to a central control server, awaiting instructions.

Anti-virus firm Trend Micro advises users to avoid the temptation to follow any links or pictures sent via MSN Messenger (unless you are sure of the origin) and to be suspicious of messages which refer to the use of social networking sites.

In other malware/social engineering news, Trend Micro reports that it took less than a day for VXers to re-direct users who want to find out more about Brokeback Mountain actor Heath Ledger's untimely death to sides harbouring malware. The attack is similar to early attempts to populate Google search results with links to maliciously constructed sites. ®