Saturday, September 25, 2021

IM Virus Mutations Up the Security Threat

A record number of instant messaging worm mutations is undermining

network security, according to new analysis.

Security and IT administrators have been aware of IM worms and viruses

for some time now. How seriously they have been taking that threat just

might be another issue, according to some analysts.

And some say it’s time to pick up the vigilance.

”Administrators probably need to ratchet up their concern,” says

Patrick Hinojosa, CTO of Panda Software U.S., an anti-virus company. ”I

see some concern out there, but I don’t see probably as much attention on

it as there should be… It’s punching a hole through the front-end

defenses and then it goes directly back to the network.”

The IMLogic Threat Center, an arm of IMlogic Inc., an instant messaging

management and security company, reports that 88 percent of IM worms

tracked have mutated at least once in the last 11 months. They also

report that there have been a record number of IM threat mutations —

meaning the malware attacking instant messaging software is increasingly

producing variants.

Art Gilliland, vice president of products at IMLogic, says there are a

few IM worms that have produced more than 100 variants over the last 10

or 11 months. Kelvir is one of them, mutating 123 times this year.

In addition, traditional email worms have begun spreading through IM. For

example the email Rbot worm, which has produced more than 600 variants

since first being discovered in email, now has more than 13 mutations

using IM for distribution.

Gilliland says between October 2004 and the same month in 2005, IM

malware grew by 1,500 percent. And comparing all of 2004 to January

through mid-November of 2005, IM malware has jumped 2,200 percent. That

adds up to 2,002 unique viruses that have been identified so far this

year, compared to 134 that were identified last year.

Gilliland adds that IM viruses pose a unique threat because of how

quickly they can spread over this particular communication software.

Email sees slower distribution. An IM malware, according to Gilliland,

could spread as quickly as to 2,000 or 3,000 machines in 15 minutes.

”We’ve seen quite a bit of activity on the mutli-variant front with IM

worms, without a doubt,” says Ken Dunham, a senior engineer for VeriSign

iDefense Intelligence based in Mountain View, Calif. ”Hackers recognize

that it’s trivial to create multiple variants. It’s easy pickin’s for

people to pick off the low-hanging fruit in the IM environment. Low

hanging fruit is the consumer on their home computer… and companies

allowing for non-compliant installation of software. They’re definitely

more at risk. If you allow people to do what they want on their computer,

then you’re at a much higher risk than admin who lock down the desktop.”

But Dunham points out that millions more people use email compared to

those using instant messaging. And since people also use a variety of IM

software — AIM, Yahoo, MSN — that also makes it harder for a hacker to

target a wide swath of IM users.

But Panda’s Hinojosa says as IM usage increases, so will the threats.

”As IM usage increases, it will continue to be more dangerous,

especially on the corporate side because it’s largely an uncontrolled

means of communication,” he says.

Similar articles

Latest Articles