Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
Video Content Creator
pramukag
Updated:
Yesterday at 6:10 AM
Ad icon
QA Engineer Intern
pramukag
Updated:
Yesterday at 6:07 AM
Ad icon
Sell your Land, House on idamata.lk for FREE
sajith.xp.pk
Updated:
Thursday at 9:03 AM
Handmade Character Soft Toys
anil1961
Updated:
Tuesday at 2:11 PM
Bodim.lk out now !
Manoj Suranga Bandara
Updated:
Jun 21, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Hackers exploit Skype API to infect Windows PCs
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="rockcity68" data-source="post: 13597915" data-attributes="member: 250998"><p>Cyber criminals are again using Skype to wreak havoc, according to Sophos's Naked Security blog. The worm they're using this time, a variant of Dorkbot, lets hackers take control of infected Windows PCs remotely via HTTP by exploiting the Skype API. From there, they send unsolicited instant messages along the lines of "lol is this your new profile pic?" followed by a URL. Clicking the link downloads a ZIP file containing malicious executable files, which Sophos has detected as Troj/Agent-YCW or Troj/Agent-YDC.</p><p></p><p>"Before you know it, your computer has been recruited into a botnet ... and could fall victim to a ransomware attack," wrote Graham Cluley, a senior technology consultant at Sophos.</p><p></p><p>Variants of the Dorkbot attack have been spotted over the past year or so, spreading via Facebook and Twitter, as well as USB sticks and IM protocols. The danger, Cluley cautioned, is that "Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users."</p><p></p><p>Skype told InfoWorld via email that it is aware of the malicious activity and is working to mitigate its impact. "We strongly recommend upgrading to the newest Skype version and applying updated security features on your computer," per the statement. "Additionally, following links -- even when from your contacts -- that look strange or are unexpected is not advisable."</p><p></p><p>It's not as though Skype users have been immune to security threats in the past, which could explain why Skype, along with Dropbox, is among the most commonly blacklisted apps in the enterprise, according to Zenprise's Q2 2012 Mobile Device Management Cloud Report. The report found that organizations have become increasingly wary of applications that reduce productivity, drain bandwidth, and have known security risks.</p><p></p><p>Skype has been dogged by security concerns for some time. For example, last year, a security consultant discovered a cross-site scripting flaw that could be used to change a user's password. Also in 2011, researchers discovered several serious security and privacy flaws in Skype that even a "high school-age hacker" could use to track not only users' locations over time but also their P2P file-sharing activity, Network World reported.</p><p></p><p>Then in July, Skype had to contend with a glitch where IMs were shared with unintended parties. Notably, Mac users haven't been immune to Skype security vulnerabilities either</p><p></p><p>source:<a href="http://www.infoworld.com/t/anti-virus/hackers-exploit-skype-api-infect-windows-pcs-204333" target="_blank">http://www.infoworld.com/t/anti-virus/hackers-exploit-skype-api-infect-windows-pcs-204333</a></p></blockquote><p></p>
[QUOTE="rockcity68, post: 13597915, member: 250998"] Cyber criminals are again using Skype to wreak havoc, according to Sophos's Naked Security blog. The worm they're using this time, a variant of Dorkbot, lets hackers take control of infected Windows PCs remotely via HTTP by exploiting the Skype API. From there, they send unsolicited instant messages along the lines of "lol is this your new profile pic?" followed by a URL. Clicking the link downloads a ZIP file containing malicious executable files, which Sophos has detected as Troj/Agent-YCW or Troj/Agent-YDC. "Before you know it, your computer has been recruited into a botnet ... and could fall victim to a ransomware attack," wrote Graham Cluley, a senior technology consultant at Sophos. Variants of the Dorkbot attack have been spotted over the past year or so, spreading via Facebook and Twitter, as well as USB sticks and IM protocols. The danger, Cluley cautioned, is that "Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users." Skype told InfoWorld via email that it is aware of the malicious activity and is working to mitigate its impact. "We strongly recommend upgrading to the newest Skype version and applying updated security features on your computer," per the statement. "Additionally, following links -- even when from your contacts -- that look strange or are unexpected is not advisable." It's not as though Skype users have been immune to security threats in the past, which could explain why Skype, along with Dropbox, is among the most commonly blacklisted apps in the enterprise, according to Zenprise's Q2 2012 Mobile Device Management Cloud Report. The report found that organizations have become increasingly wary of applications that reduce productivity, drain bandwidth, and have known security risks. Skype has been dogged by security concerns for some time. For example, last year, a security consultant discovered a cross-site scripting flaw that could be used to change a user's password. Also in 2011, researchers discovered several serious security and privacy flaws in Skype that even a "high school-age hacker" could use to track not only users' locations over time but also their P2P file-sharing activity, Network World reported. Then in July, Skype had to contend with a glitch where IMs were shared with unintended parties. Notably, Mac users haven't been immune to Skype security vulnerabilities either source:[url]http://www.infoworld.com/t/anti-virus/hackers-exploit-skype-api-infect-windows-pcs-204333[/url] [/QUOTE]
Insert quotes…
Verification
Hathara warak wissa keeyada? (Hathara wadi karanna 20)
Post reply
Top
Bottom