Home › Forums › Archives › Site News & Announcements › Instant Messaging News › General / Other IM News › Social Engineering Spreads New Plague of Web Chat Viruses
- This topic has 0 replies, 1 voice, and was last updated 24 years, 5 months ago by
BigBlueBall News.
-
AuthorPosts
-
March 21, 2002 at 6:00 am #16149
BigBlueBall News
MemberNewsFactor Network
March 21, 2002
CERT said the reports it has received indicate intruders are using automated tools to post messages to IRC or IM service users.
The enticements of pornography, free software and security — otherwise known as “social engineering” — that have been common among e-mail-borne computer viruses now have spread to instant messaging (IM) and Internet Relay Chat (IRC), according to CERT, a federally funded security center based at the Software Engineering Institute of Carnegie Mellon University.
CERT said it has received reports that “tens of thousands of systems have recently been compromised” using “social engineering attacks” via IRC or instant messaging.
The attacks attempt to trick Internet chat users into downloading what purports to be antivirus protection, improved music downloads or pornography but is actually malicious code, the center reported.
While use of social engineering among virus writers and hackers is nothing new, the IRC and IM tricks have allowed thousands of computers to be taken over and used in distributed denial-of-service (DDoS) attacks or infected with Trojan horse or backdoor programs, according to CERT.
“Although this activity is not novel, the technique is still effective, as evidenced by reports of tens of thousands of systems being compromised in this manner,” CERT said in an incident note.
Users Being Used
CERT noted that the reports it has received indicate intruders are using automated tools to post messages to IRC or IM users. The messages reportedly offer the opportunity to download software but result in systems being “co-opted by the attacker” for use in DDoS attacks or to spread malicious code.
“Its significant for a couple of reasons,” CERT Internet security analyst Allen Householder told NewsFactor. “First because of the sheer numbers — weve had tens of thousands of reports.
“Its also an audience that doesnt tend to get our message,” Householder added. “This is a home user thing.”
Malicious Mainstay
Senior director of Symantec Security Response Sharon Ruckman told NewsFactor that both virus writers and hackers have long used social engineering to dupe users.
“What weve seen is that over the years, social engineering is one of the main ways to spread any malicious activity,” she said. “Thats always been a method hackers use to come in. On the virus side, its about spreading.”
Ruckman said the best defense against falling victim to social engineering is the transfer of “best practices” to all platforms with which users communicate, including IRC and instant messaging. She warned users to “always be concerned which people are giving you information.”
-
AuthorPosts
- You must be logged in to reply to this topic.