IM Virus Mutations Up the Security Threat

With IM malware increasingly creating a sea of variants, and email worms mutating into IM threats, analysts say it's time to focus on securing instant messaging.
Posted November 16, 2005

Sharon Gaudin

A record number of instant messaging worm mutations is undermining network security, according to new analysis.

Security and IT administrators have been aware of IM worms and viruses for some time now. How seriously they have been taking that threat just might be another issue, according to some analysts.

And some say it's time to pick up the vigilance.

''Administrators probably need to ratchet up their concern,'' says Patrick Hinojosa, CTO of Panda Software U.S., an anti-virus company. ''I see some concern out there, but I don't see probably as much attention on it as there should be... It's punching a hole through the front-end defenses and then it goes directly back to the network.''

The IMLogic Threat Center, an arm of IMlogic Inc., an instant messaging management and security company, reports that 88 percent of IM worms tracked have mutated at least once in the last 11 months. They also report that there have been a record number of IM threat mutations -- meaning the malware attacking instant messaging software is increasingly producing variants.

Art Gilliland, vice president of products at IMLogic, says there are a few IM worms that have produced more than 100 variants over the last 10 or 11 months. Kelvir is one of them, mutating 123 times this year.

In addition, traditional email worms have begun spreading through IM. For example the email Rbot worm, which has produced more than 600 variants since first being discovered in email, now has more than 13 mutations using IM for distribution.

Gilliland says between October 2004 and the same month in 2005, IM malware grew by 1,500 percent. And comparing all of 2004 to January through mid-November of 2005, IM malware has jumped 2,200 percent. That adds up to 2,002 unique viruses that have been identified so far this year, compared to 134 that were identified last year.

Gilliland adds that IM viruses pose a unique threat because of how quickly they can spread over this particular communication software. Email sees slower distribution. An IM malware, according to Gilliland, could spread as quickly as to 2,000 or 3,000 machines in 15 minutes.

''We've seen quite a bit of activity on the mutli-variant front with IM worms, without a doubt,'' says Ken Dunham, a senior engineer for VeriSign iDefense Intelligence based in Mountain View, Calif. ''Hackers recognize that it's trivial to create multiple variants. It's easy pickin's for people to pick off the low-hanging fruit in the IM environment. Low hanging fruit is the consumer on their home computer... and companies allowing for non-compliant installation of software. They're definitely more at risk. If you allow people to do what they want on their computer, then you're at a much higher risk than admin who lock down the desktop.''

But Dunham points out that millions more people use email compared to those using instant messaging. And since people also use a variety of IM software -- AIM, Yahoo, MSN -- that also makes it harder for a hacker to target a wide swath of IM users.

But Panda's Hinojosa says as IM usage increases, so will the threats.

''As IM usage increases, it will continue to be more dangerous, especially on the corporate side because it's largely an uncontrolled means of communication,'' he says.

0 Comments (click to add your comment)
Comment and Contribute


(Maximum characters: 1200). You have characters left.