Threat increases from IM-based attacks

Security vendor's study shows that IM-based attacks pose rapidly growing threat.

A study released by instant messaging (IM) security vendor, IMlogic, reported that hackers and virus writers are recognizing and exploiting the opportunites presented by IM-based attacks, the numbers of which have risen sharply over the last two quarters.

The number of IM attacks such as viruses, worms, and phishing scams had increased from 20 for all of 2004 to 571 in the second quarter of 2005 alone, representing an increased threat to both enterprise users and the average consumer, the study said.

The study - performed by the IMlogic Threat Center with the support of IT security companies Symantec, McAfee, and Sybari as well as IM leaders America Online, Yahoo, and Microsoft - reported that 70 per cent of IM-based attacks target public IM networks and 30 per cent target enterprises.

"IM usage has reached critical mass and virus writers have now recognised it as a mostly undefended medium," IMlogic chief executive officer and co-founder, Francis deSouza, said. "These [viruses and worms] are mutating, high velocity, and invisible to most companies until they hit. All these factors combine to create a serious risk."

IM attacks act much like email worms and viruses, stealing information from the user's computer or turning that computer into a so-called zombie by tricking users into clicking on phony links or into opening malicious attachments.

IM-based attacks could be even more threatening because people received false instant messages from a name on their buddy list rather than a strange email address, DeSouza said.

"Having an army of zombies is the economic equivalent of having an oil well," SANS Institute analyst, Alan Paller, said. "The two most important things [for a user] to do are block all attachments on IM and to filter IM traffic so you only get it from trusted sites."

In corporate environments the Kelvir, Opanki, and Gabby worms were the most common, the study said.

Some attacks are tailored to a specific user and appear to be, for instance, a highly personalised message. The study said that these attacks made up less than one per cent of the recorded IM attacks.

For the most part IM attackers weren't sophisticated enough to single out any one user, Paller said. However rare targeted attacks might be, Paller emphasised that they were the most dangerous.

The vast majority - 86 per cent - of reported attacks involved viruses or worms that capitalised on real-time protocols. The study showed that all of the most successful IM services - AOL Instant Messenger, MSN Messenger, Windows Messenger, and Yahoo Messenger - were vulnerable to and affected by IM attacks.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Saalfield

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?