September 2, 2009 5:31 PM
- Text
Skype Snooping: Virus Eavesdrops on Calls
generic youtube internet video boradcast broadband viral global world network media (CBS/iStockphoto)
(AP)
Some computer viruses have a crude but scary ability to spy on people by logging every keystroke they type. Now hackers and potentially law enforcement have another weapon: a virus that can eavesdrop on voice conversations that go over computers instead of a regular phone line.
The capability has been shown in a new "Trojan horse" virus that records Voice over Internet Protocol (VoIP) calls through the popular Skype service. Skype calls are free or low cost and can work between two computers or between one computer and a phone.
There were 480 million Skype users worldwide at the end of June, but it's unlikely many would be hit by the new virus. It's better suited for targeted espionage rather than mass infections because criminals would have to sift through an unfathomable amount of audio recordings generated by the virus.
Law enforcement in the U.S. would presumably need a court order to surveil someone's Skype calls, but the barriers to deploying the virus might be lower for intelligence agencies and authorities in other countries.
The virus, which security firm Symantec Corp. calls the first "wiretap Trojan," doesn't target a particular vulnerability in Skype. Instead, it hooks into parts of the Windows operating system that handle audio processing. Then it intercepts all audio data coming from Skype before it's encrypted by the software, according to Symantec's analysis.
The audio gets saved as MP3 files and can be sent to computers controlled by the criminals.
"It's more interesting than dangerous," said Kevin Haley, director of Symantec Security Response. "It's an espionage tool. That's its clear purpose. It's not practical for any type of broad-based attacks."
The virus was designed and released by Ruben Unteregger, a Swiss programmer who said he started researching on his own before turning it into a project for his employer, ERA IT Solutions.
In 2006 the software company was reported by the Swiss newspaper SonntagsZeitung to have been working on a VoIP-cracking virus for the Swiss government, an account Unteregger said he couldn't confirm because of a nondisclosure agreement he signed for the project.
ERA IT Solutions says it never had an order from a government agency to develop the program, and that it stopped working on it when Unteregger left the company last year.
"This is Ruben's affair only," said company representative Riccardo Gubser.
Unteregger said in an e-mail interview with the AP that his goal in releasing the virus' programming code was to make people aware that "we are now becoming a surveillance society" and that "police Trojans are reality and questionable."
The capability has been shown in a new "Trojan horse" virus that records Voice over Internet Protocol (VoIP) calls through the popular Skype service. Skype calls are free or low cost and can work between two computers or between one computer and a phone.
There were 480 million Skype users worldwide at the end of June, but it's unlikely many would be hit by the new virus. It's better suited for targeted espionage rather than mass infections because criminals would have to sift through an unfathomable amount of audio recordings generated by the virus.
Law enforcement in the U.S. would presumably need a court order to surveil someone's Skype calls, but the barriers to deploying the virus might be lower for intelligence agencies and authorities in other countries.
The virus, which security firm Symantec Corp. calls the first "wiretap Trojan," doesn't target a particular vulnerability in Skype. Instead, it hooks into parts of the Windows operating system that handle audio processing. Then it intercepts all audio data coming from Skype before it's encrypted by the software, according to Symantec's analysis.
The audio gets saved as MP3 files and can be sent to computers controlled by the criminals.
"It's more interesting than dangerous," said Kevin Haley, director of Symantec Security Response. "It's an espionage tool. That's its clear purpose. It's not practical for any type of broad-based attacks."
The virus was designed and released by Ruben Unteregger, a Swiss programmer who said he started researching on his own before turning it into a project for his employer, ERA IT Solutions.
In 2006 the software company was reported by the Swiss newspaper SonntagsZeitung to have been working on a VoIP-cracking virus for the Swiss government, an account Unteregger said he couldn't confirm because of a nondisclosure agreement he signed for the project.
ERA IT Solutions says it never had an order from a government agency to develop the program, and that it stopped working on it when Unteregger left the company last year.
"This is Ruben's affair only," said company representative Riccardo Gubser.
Unteregger said in an e-mail interview with the AP that his goal in releasing the virus' programming code was to make people aware that "we are now becoming a surveillance society" and that "police Trojans are reality and questionable."
Popular Now in SciTech
- Apple iPad 3 rumors: thicker, sharper, coming soon
- Tesla's Model X: Finally, an electric car we all want
- Retro Duo will play your old Nintendo games
- iPad 3 mini on the way, says analyst
- Apple iPad 3 rumors resurface, sources say March release
- Apple iPhone 5 rumors, reports say June release
- Happy 50th to computer game Spacewar
- Obama's 2012 campaign playlist now on Spotify
- Google developing home entertainment system
- Facebook graffiti artist David Choe, from homeless to millions
- FBI releases Steve Jobs background report
- Facebook required for Spotify account, here's a trick
- Apple iPad 3 rumors, let's get real
- Apple faces $1.6 billion iPad trademark lawsuit
- Ethical iPhone 5 petitions head to Apple stores
- Hackers release Symantec pcAnywhere source code
- Shocking Stats on Texting While Driving
Latest CBS News Headlines
on Facebook
on CBS News
- Smith stops 38 shots, Coyotes top Blackhawks 3-0
- Whitney Houston's voice will never be forgotten
- Reactions to Whitney Houston's death
- Colaiacovo scores in OT to lift Blues over Avs 3-2
on Facebook
- Adele sings a cappella for Anderson Cooper
- Occupy protestors kicked out of CPAC
- CPAC: Will Sarah Palin spring a surprise?
- Beyonce and Jay-Z post first photos of Blue Ivy Carter
on CBS News






