Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
Peter Parkes

A little bit about Trojan.Peskyspy

By My status Peter Parkes on September 3, 2009 in In the news.

Some of you may have seen stories circulating about a ‘trojan’ (a malicious piece of software) which can listen in to your Skype calls – and I’d like to set the record straight on two points.

  • In order for this trojan to ‘listen in’, it has to be run on your computer, which means that your computer is already compromised – e.g. by a virus.
  • It doesn’t exploit the Skype software; instead, it ‘listens in’ to the audio data which is transferred between Skype and your computer hardware – your headset and microphone, for example – and it does this using processes which are available in the Microsoft Windows operating system. It’s like standing next to someone when they are talking :)

Screen with padlockSo, what should you do? All the usual security recommendations still apply – make sure you don’t open files from people you don’t trust, stay current on patches and updates for your computer and use an up-to-date anti-virus program.

If you’re looking for more details, the security experts at Symantec sum things up pretty nicely over on their blog:

What this threat is doing is actually grabbing the sound coming from the audio devices plugged into the computer. It does this by hooking various Windows API calls that are used in audio input and output. It then is able to intercept all audio data traveling between the Skype process and the underlying audio device. The extracted audio data is then saved to .mp3 files and stored on the computer.

Because the Trojan listens in the data traveling between the Skype process and the audio device, it gathers the audio independently of any application-specific protocols or encryption applied by Skype when it passes voice data at the network level. Essentially, it sits below these security measures, recording the audio at the Windows level—before outbound audio from the microphone gets to Skype and after incoming audio leaves Skype and reaches the speakers.

Finally, the Trojan contains a back door, which enables an attacker to have the stolen audio conversations sent to a predetermined location, where they can later be listened to.

In terms of impact, we don’t see this threat gaining much of a foothold out in the wild. What we’ve seen is largely proof-of-concept and does not contain any method to spread from one computer to another. However, it is possible that we will see variations on this Trojan theme in the future. With this in mind we recommend keeping your virus definition and IPS signatures up-to-date.

Bookmark and Share

View blog reactions

Comments

"We don't see this threat gaining much of a foothold out in the wild"? I was under the impression that the trojan was required on all computers in Germany... or was it that the police are allowed to install said trojan? Something like that.

bigbrownchunx | Thursday, Sep 3

@bigbrownchunx while (or course) we happily co-operate with German authorities where relevant, they haven’t imposed that requirement on us :)

peterparkes | Thursday, Sep 10

Comment on this post

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Please read our comment guidelines before posting your comment.

Back to index
Subscribe to RSS feed
Subscribe by email
Skype Blogs
  • Share Skype Blog
  • Heartbeat
  • Developer Zone
  • Business
  • Skype Gear
  • Security
  • Garage
  • Mac
  • Linux
  • Eesti keeles
  • 日本語
  • Česky
  • Deutsch
  • Français
  • Italiano
  • Brasil
  • United Kingdom
  • Polski
  • United States
  • 한국어
  • Recent posts
  • New record: 20 million people on Skype at the same time
  • Working with the USO to bring families together
  • Dr Jonathan Rosenberg Joins Skype as Chief Technology Strategist
  • We've settled with Joltid
  • Get the magic of Skype on your mobile
  • Latest comments
  • @bigbrownchunx while (or course) we happily co-operate with German authorit …
  • "We don't see this threat gaining much of a foothold out in the wild"? I w …
Archives
  • Independent blogs
    The views expressed in the third-party sites reflect those of their creators and are not necessarily shared or endorsed by Skype.
  • eBay Chatter blog
  • Alec Saunders
  • Anders Jacobsen
  • Andrew Hansen
  • Andy Abramson
  • Aswath
  • Dan York
  • Dina Mehta
  • Ike Roelfsema
  • Jaanus Kase
  • Jean Mercier
  • Jeff Pulver
  • Joerg Droege
  • Joi Ito
  • Lars Kamp
  • Mark Evans
  • Martin Geddes
  • Martin Varsavsky
  • Neville Hobson
  • Om Malik
  • Richard Stastny
  • Rich Tehrani
  • Robert Scoble
  • Ross Mayfield
  • Skype Journal
  • Solomon Kay
  • Stuart Henshall
  • Tom Evslin
  • Tom Keating
About us · Partners · Jobs · Prices · Security
Privacy policy · Legal · © 2009 Skype Limited