AOL Confirms AIM Trojan

NEW YORK – America Online instant messenger users have been hit recently with a trojan, the company announced, and a select number of AIM screen names have been suspended as a result.

The New York-based media conglomerate would not disclose the number of accounts infected by the malware, but said that its in-house instant messenging spim unit first identified the problem as the Oscarbot trojan and took action by shutting down certain accounts to stop the spread. Users whose accounts were suspended reportedly lost the entire contents of their buddy lists.

The Oscarbot, which first emerged as Doyorg, is programmed to specifically wreak havoc on AOL's AIM product and quickly spreads through buddy lists. According to eWeek, the trojan spreads through a URL embedded in the infected IM that uses the lure "Check out this" or "I thought you'd want to see this" to get the user to click through. Once the user clicks through, they are asked to run an executable file that installs the trojan.

Oscarbot can also contact a remote Internet relay chat server and log on to a specified channel and wait for further instructions from a remote user. Once installed on a computer, the malware creates a copy of itself in the Windows system folder and edits certain registry keys to ensure that it is run as a service when the system starts up.

Since the trojan was first discovered, AOL's AIM unit has been flooded with angry calls and emails from users who have had their accounts suspended and buddy lists wiped clean. AOL has requested that users whose accounts have been suspended contact the company's IM department for further instructions.

In the meantime, Graham Cluley of Sophos is urging companies to consider whether using IM is worth the risk of having corporate networks invaded.

"Fundamentally, many businesses will have to ask their staff if they really need IM for their day-to-day work, and if not, it may be more sensible to take it away," he told ComputerWorld. "We're certainly seeing more instant messaging malware being written, although they haven't yet had the same kind of impact as email-aware worms or Internet worms."

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Master Nico Relaunches Site Through YourPaysitePartner

Master Nico has relaunched his official website through YourPaysitePartner (YPP).

Federal Judge Grants Partial Halt of Florida AV Law

The United States District Court for the Northern District of Florida, Tallahassee Division, has granted a preliminary injunction against HB 3, the state's age verification law, as a lawsuit filed by two online trade associations challenging the law makes its way through the courts.

Aylo Releases Statement on Suspending Access to Pornhub in France

Technology and media company Aylo, which operates adult sites including Pornhub, YouPorn, and Redtube, has released a public statement regarding its decision to block access to its sites in France.

Pineapple Support to Host Wellness Sessions at Bucharest Summit

Pineapple Support is hosting free group and one-on-one therapy sessions at Bucharest Summit, June 3-5.

Pornhub Blocks Access in France in Response to SREN Law

Pornhub parent company Aylo has opted to block access to its sites in France rather than comply with age verification requirements under the country’s Security and Regulation of the Digital Space (SREN) law.

ASACP Highlights Study on Parental Controls

The Association of Sites Advocating Child Protection (ASACP) is highlighting the results of a study on the underutilization of parental controls.

Sydney Screams Launches New Site Through Grooby's Blue.xxx

Sydney Screams has launched her new membership site, SydneyScreams.xxx, through Grooby's website management company Blue.xxx.

Mistress Mystii Is LoyalFans' 'Featured Creator' for June

LoyalFans has named Mistress Mystii as its Featured Creator for June.

Show More