On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

August 28th, 2009

Source code for Skype eavesdropping trojan in the wild

Posted by Dancho Danchev @ 4:20 am

Categories: Anti Virus, Botnets, Browsers, Complex Attacks, Hackers, Malware, Pen testing, Responsible disclosure, Spyware and Adware

Tags: Trojan Horse, Skype Technologies S.A., Spyware, Spyware, Adware & Malware, Government, Viruses And Worms, Security, Dancho Danchev

Earlier this week, Swiss programmer Ruben Unteregger who has been reportedly working for a Swiss company ERA IT Solutions responsible for coding government sponsored spyware, has released the source code of a trojan horse that injects code into the Skype process in order to convert the incoming and outgoing voice data into an encrypted MP3 available at the disposal of the attacker.

Here’s how the trojan, currently detected as Trojan.Peskyspy, works:

“When the Trojan is executed, it injects a thread into the Skype process and hooks a number of API calls, allowing it to intercept all PCM audio data going between the Skype process and underlying audio devices. Note: Since the Trojan listens to the data coming to and from the audio devices, it gathers the audio independently of any application-specific protocols or encryption applied by Skype when it passes voice data at the network level.

Note: The incoming and outgoing audio data are stored in separate .mp3 files. The Trojan also opens a back door on the compromised computer, allowing an attacker to perform the following actions:
- Send the .mp3 to a predetermined location
- Download an updated version
- Delete the Trojan from the compromised computer”

Skype is often dubbed a “national security threat” by governments all across the globe due to their — at least publicly acknowledged — inability to crack the 256-bit encryption VoIP calls.

And while some of these governments are reportedly spending surreal amounts of tax payer’s money (Rental of the Skype-Capture-Unit per month and instance EUR 3.500) in order to achieve their objectives, others are taking the cost-effectiveness path by attacking the weakest link in the process - the end user infected with a targeted DIY government sponsored spyware recording all ongoing and incoming Skype calls, thereby bypassing the need to attack the encryption algorithm.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 52 Talkback(s)
No way...
Every since I accidentally eavesdropped on a lover's conversation back in the seventies, I've realized you shouldn't say anything over the air, or wire, that you shouldn't release to the public.
... (Read the rest)
Posted by: JCitizen Posted on: 09/05/09  (Edited: 09/05/09 @ 09:07) You are currently: a Guest | | Terms of Use
Social Engineering?  Albee_Freeoneday | 08/28/09
Just one of the many reasons . . .  wgraue | 08/28/09
" Just one of the many reasons..."  Kaptah | 08/28/09
dogma  Louis Ross Focke | 08/28/09
" dogma "  Kaptah | 08/28/09
whoa,  Louis Ross Focke | 08/28/09
NO, I do not agree with you,...  theguru1995@... | 08/28/09
Wow...  jasonp@... | 08/28/09
Interesting  tracy anne | 08/29/09
"I want to run a Windows Wannabee or I can fire up the Apple iMac" ?  Appreciate-Tech | 08/29/09
" I can fire up the Apple iMac"  Kaptah | 08/31/09
Go OS X 10.6  Appreciate-Tech | 08/29/09
No money  dleon63 | 08/29/09
Don't bother  dleon63 | 08/29/09
RE: Source code for Skype eavesdropping trojan in the wild  andreas.tanzer@... | 08/28/09
a few bits of information  Louis Ross Focke | 08/28/09
Yes, spies from both sides...  JCitizen | 09/05/09
Good for him?  spstanley | 08/28/09
RE: Source code for Skype eavesdropping trojan in the wild  danm50 | 08/28/09
Thats for sure...  JCitizen | 09/05/09
RE: Source code for Skype eavesdropping trojan in the wild  wgraue | 08/28/09
Talk about the wrong way...  jasonp@... | 08/28/09
I suspect it was already in the wild...  JCitizen | 09/05/09
Not Skype's only problem  Dorkyman | 08/28/09
Skype Software and the Skype Services at Your own risk.  Stan57 | 08/28/09
A Deal with the Devil  rod.boggess@... | 08/28/09
Darned if you do, darned if you don't  slylabs13 | 08/28/09
Darned if  Louis Ross Focke | 08/28/09
I agree with you LRF....  theguru1995@... | 08/28/09
However, in the final analysis.. LRF  Kaptah | 08/28/09
Warm and Fuzzy  Louis Ross Focke | 08/28/09
In the end...  RS9 | 08/30/09
In the end...  Kaptah | 08/31/09
All I know...  JCitizen | 09/05/09
RE: Source code for Skype eavesdropping trojan in the wild  intlfam | 08/28/09
RE: Source code for Skype eavesdropping trojan in the wild  rebecca01@... | 08/28/09
RE: Source code for Skype eavesdropping trojan in the wild  x3dre@... | 08/28/09
Bypass the bypass...  redking44 | 08/28/09
RE: Source code for Skype eavesdropping trojan in the wild  phatkat | 08/28/09
True..  JCitizen | 09/05/09
"If you don't want it known ... "  Tony R. | 08/28/09
pros and cons  bildr | 08/28/09
RE: Source code for Skype eavesdropping trojan in the wild  vilppuu@... | 08/29/09
Eavesdropping on what?  rrascal | 08/29/09
this is all irrelavant old hat  On Site PC | 08/29/09
Should we stop using Skype?  snesich | 08/30/09
No...  JCitizen | 09/05/09
RE: Source code for Skype eavesdropping trojan in the wild  snesich | 08/30/09
No way...  JCitizen | 09/05/09
Use Skype on other platforms...  kenmo | 08/31/09
RE: Source code for Skype eavesdropping trojan in the wild  JeramieH | 08/31/09
RE: Source code for Skype eavesdropping trojan in the wild  DDSCentral | 08/31/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads