Skype users are being hit with a Trojan that using the infected machine to reach out and infect the user's friends and colleagues.
Dan Hubbard, a vice president of security research at Websense, said while the Trojan isn't widely spread at this point, it is making its way across the network. While the code itself is not self-propagating, when it runs, a URL is sent to everyone in the user's contact list. If their Skype program is running, a message will pop up, luring the user to click on a link, infecting them and continuing the malicious cycle.
The Trojan also opens a back door in the user's computer, enabling a hacker to get into the machine and steal the user's information or use the computer to send out spam or even a denial-of-service attack.
"Clicking on unsolicited messages in Skype is just not a good idea," said Hubbard in an interview. "Users need to get the message."
Skype is a free Voice over IP service, that enables users to record and playback audio.
The Websense advisory noted that Skype users receive a message that says "Check up this," with a URL containing a hyperlink. When users click on the link, they are redirected to a site hosting a file named file_01.exe. Users are prompted to run the file. If the user runs the file, several other files are downloaded and run.
This is not an exploit taking advantage of a vulnerability in Skype, Websense noted.
A screen shot is available in the alert. Websense also offers tips on preventing this kind of attack.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.