Threat increases from IM-based attacks

Security vendor's study shows that IM-based attacks pose rapidly growing threat.

A study released by instant messaging (IM) security vendor, IMlogic, reported that hackers and virus writers are recognizing and exploiting the opportunites presented by IM-based attacks, the numbers of which have risen sharply over the last two quarters.

The number of IM attacks such as viruses, worms, and phishing scams had increased from 20 for all of 2004 to 571 in the second quarter of 2005 alone, representing an increased threat to both enterprise users and the average consumer, the study said.

The study - performed by the IMlogic Threat Center with the support of IT security companies Symantec, McAfee, and Sybari as well as IM leaders America Online, Yahoo, and Microsoft - reported that 70 per cent of IM-based attacks target public IM networks and 30 per cent target enterprises.

"IM usage has reached critical mass and virus writers have now recognised it as a mostly undefended medium," IMlogic chief executive officer and co-founder, Francis deSouza, said. "These [viruses and worms] are mutating, high velocity, and invisible to most companies until they hit. All these factors combine to create a serious risk."

IM attacks act much like email worms and viruses, stealing information from the user's computer or turning that computer into a so-called zombie by tricking users into clicking on phony links or into opening malicious attachments.

IM-based attacks could be even more threatening because people received false instant messages from a name on their buddy list rather than a strange email address, DeSouza said.

"Having an army of zombies is the economic equivalent of having an oil well," SANS Institute analyst, Alan Paller, said. "The two most important things [for a user] to do are block all attachments on IM and to filter IM traffic so you only get it from trusted sites."

In corporate environments the Kelvir, Opanki, and Gabby worms were the most common, the study said.

Some attacks are tailored to a specific user and appear to be, for instance, a highly personalised message. The study said that these attacks made up less than one per cent of the recorded IM attacks.

For the most part IM attackers weren't sophisticated enough to single out any one user, Paller said. However rare targeted attacks might be, Paller emphasised that they were the most dangerous.

The vast majority - 86 per cent - of reported attacks involved viruses or worms that capitalised on real-time protocols. The study showed that all of the most successful IM services - AOL Instant Messenger, MSN Messenger, Windows Messenger, and Yahoo Messenger - were vulnerable to and affected by IM attacks.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Saalfield

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender’s best-in-class security solutions have been awarded Product of the Year. Get cybersecurity that 500 MILLION users already have and trust!

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?