Look before you click
Antivirus firm f-secure reports a hostile bot (bot farm?) uses Skype's client API to send potentially dangerous messages to unsuspecting users.
We have two reports of people receiving links to a Warezov-infected file via Skype.
Now, some older Warezov variants have used other Instant Messaging client in a similar fashion, but not Skype.
The messages looked like this:
![]()
We detect the binary at that download location as Warezov.ly.


Comments
Here's something serious - my account appears to have been hijacked, and Skypeout calls being automatically made while I am asleep.
Oddly enough - to my own mobile number which is in my Skype Out contact list.
It's a careful scheme, with testing about 2 weeks ago in the wee hours while I am asleep, and then a 2 hour call to my mobile phone.
Strange thing is that my mobile phone was off and there is no voicemail and no record of a call, except in Skype.
The first three "trials" lasted for exactly 48 seconds each, all in the dark hours when my machine was unattended.
This did raise my curiousity but I couldn't bebothered battling the Skype "Help" system. In fact I think I send a query which came back with references to other answers which were not relevant and I could not spend the effort to go further.
But in the latest case my auto-recharge started popping over and I spent time tracking down why and where and discovered this 2 hour call.
I don't have any call forward enabled, and therefore it could not be an incoming call which activated the event.
This is a real security nightmare, and has cost me Euro20 in one hit. Calling myself at 4.33am for 2 hours to my switched off mobile phone doesn't make any sense.
I am not sure who would benefit, but it is not me. I am turning off all auto-recharges and also removing Skype-out contacts - which ultimately makes Skype relatively useless for me.
My "google" on "skype hijack" did not reveal any other reported cases but perhaps time will tell.
Walter Adamson
Melbourne, Australia
Posted by: Walter Adamson | June 7, 2007 08:11 PM