December 20, 2005 10:10 AM PST

Santa IM worm hits AOL, MSN and Yahoo

A Santa Claus worm is attempting to trick America Online, Microsoft MSN and Yahoo instant-messaging users into clicking on a file that delivers unwanted software to a victim's computer.

The IM.GiftCom.All worm attempts to dupe IM users into thinking an acquaintance has sent them a link to a harmless Santa Claus file, according to a security advisory issued Tuesday by IMlogic.

People who click on the file will see an image of Santa, but what they are less likely to notice is a so-called rootkit being installed onto their system. A rootkit is a tool designed to go undetected by the security software used to lock down control of a computer after an initial hack. The malicious attacker can then distribute messages to the user's IM contacts, using a similar technique to lure the unsuspecting acquaintance to click on the link.

The Santa worm is the latest tactic to be used on IM networks. Past tricks have included offers of movie clips to the latest release of "Star Wars" that instead led to an infected computer.

Worms on IM networks can spread rapidly. They appear as a message from a buddy with a link that looks innocent, but in fact points to malicious code somewhere on the Internet. Once the user clicks on the link, malicious code is installed and runs on the computer. The worm then spreads itself by sending messages to all names on the victim's contact list.

IMlogic is rating the IM.GiftCom.All worm a "medium" security threat.

"This worm is a medium threat in terms of its distribution, but in terms of the damage it can create, it's a more severe threat," said Art Gilliland, vice president of products for IMlogic.

"It's not a very happy delivery," he added.

CNET News.com's Joris Evers contributed to this report.

6 comments

Join the conversation!
Add your comment
merry christmas
Merry Christmas Windows users. You deserve it.
Posted by (96 comments )
Reply Link Flag
If there really was a god...
If you really were god you'd make Linux that could actually run our applications instead of allowing the "inferrior" product to capture the whole desktop marketplace!
Posted by Xpheyel (32 comments )
Link Flag
That's nice.
Coal for you bud.
Posted by Sboston (498 comments )
Link Flag
MSN Messenger was down
I figured the service was down hours. It could be related
Posted by Ilgaz (573 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.