Aug30 |
11:07 pm (UTC-7) | by
Bernadette Irinco (Technical Communications) |
TrendLabs researchers were alerted of a newly released Proof-of-Concept (PoC) that listens and records voice calls carried out via Skype. Trend Micro detects this as TROJ_SPAYKE.C. Skype is a popular application used for making voice over IP (VoIP) calls.
Upon execution, the DLL component (also detected as TROJ_SPAYKE.C) intercepts Skype traffic and hooks the send and recv APIs. This is done before Skype encrypts the traffic it sends to other users. This enables the Trojan to save all gathered information as audio files, which could then be sent to a malicious user. Here’s a screenshot of the captured information:

Figure 1. Sample of intercepted traffic
This poses no threat as of the moment; it only collects information but does not decrypt the said information and consequently send it to a remote user. However, future attacks that do engage in information theft cannot be ruled out.
Users are advised not to give away any crucial information when conversing online to prevent info theft. Trend Micro protects users from this attack through the Trend Micro Smart Protection Network.
Share this article |
|
17 Responses to “Trojan Targets Skype Users”
Trackbacks
- TrendMicro (TrendMicro)
- o0splitpaw0o (o0splitpaw0o)
- iia_security (Terry)
- _third (third marquez)
- epcdoctor (Ernie)
- chrispeoples (chris peoples)
- KentuckyExtIT (UK Extension IT NEWS)
- JITParenting (Marissa Stone)
- DeclanmWaters (Declan Waters)
- Trojan Targets Skype Users « Friendly Computers Virus Alerts
- UnderForge of Lack » Blog Archive » 2009.09.01 火曜日
- wrstech (WRS Technology)
- petervogel (Peter Vogel)
- Daily Digs – 08.31.2009 « Security Stallions Blog
- Proof-of-Concept Trojan Targets Skype Users | Kabatology ~ Open Source, Linux




August 31st, 2009 at 1:03 am
I think you analysed dll injection poc rather than analysing real skype recorder component. funny, you guys just write anything…
November 19th, 2009 at 2:59 pm
,<>..] blog.trendmicro.com is one great source of tips on this issue,<>..]