Skype plug-in turns out to be a data thief

VoIP company warns against supposed security package.

Archive notice: This article was originally published on October 19, 2007. Links and embedded videos are preserved as part of the historical record.

The VoIP company Skype is currently warning about the “Skype Defender” plug-in in its blog. The program promises that after installation the user will have a particularly secure variant of the Skype client. In fact, the software ultimately turns out to be a Trojan that spies on user data. Because of its popularity among Internet users, the VoIP client is increasingly coming into the sights of data thieves.

Users who run the installation program receive a message after completion in which they are asked to enter their Skype user login and password. The login screen is of course fake, but nearly identical to the genuine Skype login window. Once the user has entered his data, an error message appears according to which the user data entered are incorrect. According to Skype, the malware sends not only these data to a website in the background, but also user names and passwords that are stored in Internet Explorer.

The Internet telephony provider states that it has meanwhile alerted the security companies to the fake plug-in. Removal is said to be possible both via antivirus software and manually. For the latter, it is merely necessary to delete the file “65404-SkypeDefenderSetup.exe”, according to Skype.

The security experts from McAfeem explained that the current Skype Trojan has no distribution routine and therefore does not send itself to other users. The success of the malicious program is based on the principle of social-engineering techniques. The programmers of these programs trust that their unsuspecting victims will spread the software themselves by posting the download link in relevant forums and thus inducing further users to install it.