Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Trojan.Peskyspy—Listening in on your Conversations

Symantec Security Response
August 27th, 2009
Tags: Endpoint Protection (AntiVirus), Security, Security Response
Facebook Twitter

In the last few years, voice over IP (VoIP) has gained a significant foothold in the realm of voice communication. In some arenas the technology has supplanted traditional telecommunication devices, becoming a technology many of us can no longer imagine going without.

As is often the case, when something gains a foothold in software and networking technology, it becomes a target of malicious code writers. This week we’ve seen the release of a Trojan horse called Trojan.Peskyspy that records VoIP communications, specifically targeting Skype—one of the today’s most popular VoIP applications. What we’re looking at is something that could be considered the first “wiretap Trojan”.

Now before going into the details of this threat, we’d like to point out that its existence isn’t due to any problems with Skype itself. In this case, Skype has simply become a victim of its own popularity, most likely being targeted simply because it has such a large install base. This threat could just have easily been crafted to take advantage of any one of the myriad of other VoIP applications, and it’s likely we’ll see other threats in the future that do just that.

What this threat is doing is actually grabbing the sound coming from the audio devices plugged into the computer. It does this by hooking various Windows API calls that are used in audio input and output. It then is able to intercept all audio data traveling between the Skype process and the underlying audio device. The extracted audio data is then saved to .mp3 files and stored on the computer.

Because the Trojan listens in the data traveling between the Skype process and the audio device, it gathers the audio independently of any application-specific protocols or encryption applied by Skype when it passes voice data at the network level. Essentially, it sits below these security measures, recording the audio at the Windows level—before outbound audio from the microphone gets to Skype and after incoming audio leaves Skype and reaches the speakers.

Finally, the Trojan contains a back door, which enables an attacker to have the stolen audio conversations sent to a predetermined location, where they can later be listened to.

In terms of impact, we don’t see this threat gaining much of a foothold out in the wild. What we’ve seen is largely proof-of-concept and does not contain any method to spread from one computer to another. However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date.

Special thanks to Karthik Selvaraj for his analysis of this threat.

+3 (3 votes)
  • Symantec Security Response's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Phishing Site Uses Katrina Kaif as Bait
    Mathew Maniyara - July 29, 2010
  • W32.Stuxnet Variants
    Liam O Murchu - July 29, 2010
  • Tracking Cookies
    Ben Nahorney - July 28, 2010
  • After Football, Scammers Pursue the Cricket World Cup
    Mathew Maniyara - July 28, 2010
  • Fraudsters Offering Free Mobile Phone Airtime
    Mathew Maniyara - July 28, 2010

Blog Tags

10.x 11.x 2010 State of Enterprise Security Report 419 scam 9.x and Earlier Adobe Acrobat Adobe Flash Adobe Reader Advanced Persistent Threats Amazon Antivirus2010 Apple Backdoor.Tidserv Backdoor.Trojan Brazil Brightmail Gateway Brightmail IQ Clickjacking Cricket World Cup 2011 DNS poisoning Earth Day Email Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security FIFA Father's Day Gary Coleman General Symantec Google ISTR XV IT Healthcare Landscape IT Risk Management Infostealer.Bancos Infostealer.Gampass Internet Security Threat Report Java Katrina Kaif Live PC Care Malicious Code Michael Jackson Microsoft Microsoft Patch Tuesday Misleading Applications Mobile & Wireless Mobile Security Mother's Day Online Fraud Orkut PDF PDF spam Password Management Restore SEO Poisoning Security Security Risks Security Trends 2010 Soccer Social networking South Africa Spam Survey Sykipot Symantec State of Spam & Phishing Report SymbOS.Exy Symbian Tmphider Tracking Cookie Trojan.Bredolab Trojan.Dropper Trojan.FakeAV Trojan.Loginck Trojan.Mebroot Trojan.Pidief Trojan.Pidief.I Trojan.Pidief.J Trojan.Twebot Trojan.Vundo Trojan.Zbot Trojan.Zlob Trojan.Zlob.P VirusDoctor Vulnerabilities & Exploits W32.Changeup W32.Downadup W32.Koobface W32.Qakbot W32.Sality W32.Stuxnet W32.Stuxnet!lnk W32.Temphid W32.Virut Windows World Cup 2010 World Expo 2010 Zeus directory harvest attack facebook fakeav phishing rogue antivirus rootkit scams social media twitter typosquatting volcano zero-day vulnerability
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com