January 10, 2006 9:51 AM PST

Study: Instant-messaging attacks rose in 2005

Security attacks over instant-messaging networks became more prevalent in 2005, according to a new study.

Microsoft's MSN network experienced the largest number of IM security incidents in both 2004 and 2005, while year-on-year incident growth rates were largest on America Online's AIM network, according to the report, published Monday by IM security vendor FaceTime Communications.

In 2005, MSN had a 57 percent share of the attacks, AOL had 37 percent and Yahoo had 6 percent, FaceTime said in its "Impact report: Analysis of IM & P2P Threats in 2005."

While the incidence rate of attacks over IM is still low compared with e-mail-borne attacks, the rate appears to be increasing rapidly. There were 778 incidents recorded in the fourth quarter of last year compared with 59 in the first quarter, according to the report.

"IM threats are extremely challenging for corporate IT staff because they utilize real-time communications channels and proven social engineering techniques over worldwide IM networks to propagate significantly faster than e-mail-based attacks," FaceTime said in a statement.

Worms and rootkits were at the heart of the main incidents in 2005, said Chris Boyd, security research manager at FaceTime who also warned of the growing danger of cross-network attacks.

"Hacker groups are getting more sophisticated and are beginning to attack across multiple networks. In 2004, AOL experienced the most attacks. But in 2005 there were more crossovers from AOL to the MSN network, as MSN became more popular with users," Boyd said. "There's some really nasty stuff coming through the AOL network, and it's AOL that's being used as a jump-off for other networks."

FaceTime said that exploits can jump networks through IM "consolidation" applications, such as Trillian or Gaim, which let people combine contacts from multiple IM networks on one list.

Boyd also warned that the hackers are working on new exploits. "Hacker groups have large (compromised) server farms to experiment with propagating exploits. They hide Trojans and viruses, and control these botnets via IRC," he said.

MSN declined to comment specifically on the FaceTime statistics, but agreed that the threat risk via IM networks was increasing.

"Unfortunately, over the last year, the industry has seen viruses and other online threats spread through IM systems, often via Web site links," an MSN representative said. "We recommend that customers do not click on attachments or links in IM without confirming their validity with the person who sent them."

AOL had not commented on FaceTime's statistics at the time of writing.

FaceTime claimed last November that one hacker group had taken control of 17,000 PCs using an IM worm, and Boyd said this area was still causing problems. "The main and nastiest infections come from the Middle East. We've found a viper nest of hacker dens there," he said. "We've found that lots of hardcore Middle Eastern hacker groups have embraced IM as a launchpad for attacks."

The motivation for these attacks isn't financial, he claimed: "For these gangs, financial gain is less important than making serious political statements. They engage in Web page defacement, and some claim the war as motivation," said Boyd. "The FBI is involved--they've looked at the data we've collected and have used it as a basis for investigation."

The FBI would not confirm or deny whether the data had been passed to them. "We encourage individuals and organizations to come forward to report any suspected crime, but provide confidentiality for them," an FBI official said.

Tom Espiner reported for ZDNet UK.

See more CNET content tagged:
FaceTime Communications, IM Network, IM, America Online Inc., Trillian

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.