Skip to main content

Wed, 20 Jul 2005 iTunes worm is Windows spyware threat

Jonny Evans


  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

An initial signal indicating that Apple's success with iTunes may soon attract hackers has emerged, according to security firm Trend Micro.

A new worm, WORM_OPANKI.Y, is circulating online. It poses as an iTunes file and is spreading using AOL Instant Messenger (AIM). While it does not affect Mac users, it does affect most breeds of the Windows OS.

Question of the day!

Mark Hattersley
Editor in Chief

Do you share your creations online?

Question of the day!

Do you share your creations online?

% of Macworld readers agree with you

Yes
TBC
No
TBC

What do you create and how do you share it?

124 characters remaining

Follow the conversation at @TabletChat

paintings & illustrations, mostly, which i upload to flickr.RT @fragmentedm

I draw manga/anime characters. I also do graphic design and photography.RT @spialelo

Yes. I usually put them up on my #deviantart account for feedback on how to improve.RT @spialelo

Beware “exe” files bearing gifts

The worm poses as a file named "iTunes.exe" in an attempt to trick users, "into thinking that this worm is associated with a legitimate product," Trend Micro warns.

However, when activated the worm actually sends a message to all online contacts of an affected user, which reads, "this picture never gets old". Each message has a link to a URL where users download a file that appears to be a JPEG.

Also when activated, the software will begin to download spyware and pop-ups. It also tracks Internet sites infected users visit.

Backdoor worm

Trend Micro also warns: "This worm has backdoor capabilities. It opens a random TCP port and connects to the Internet Relay Chat (IRC) server xyz.legi0n.net. Once connected, it joins the IRC channel #fate, where it listens for commands from a remote malicious user. It then executes these commands locally on affected machines."

It's not a major threat, according to the security firm. It has not yet spread too widely, the firm adds.

Email A Friend

Email this article to a friend or colleague:



PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

<<prev article | back to news index | next article>>


Latest News


More news...