AOL Confirms AIM Trojan

NEW YORK – America Online instant messenger users have been hit recently with a trojan, the company announced, and a select number of AIM screen names have been suspended as a result.

The New York-based media conglomerate would not disclose the number of accounts infected by the malware, but said that its in-house instant messenging spim unit first identified the problem as the Oscarbot trojan and took action by shutting down certain accounts to stop the spread. Users whose accounts were suspended reportedly lost the entire contents of their buddy lists.

The Oscarbot, which first emerged as Doyorg, is programmed to specifically wreak havoc on AOL's AIM product and quickly spreads through buddy lists. According to eWeek, the trojan spreads through a URL embedded in the infected IM that uses the lure "Check out this" or "I thought you'd want to see this" to get the user to click through. Once the user clicks through, they are asked to run an executable file that installs the trojan.

Oscarbot can also contact a remote Internet relay chat server and log on to a specified channel and wait for further instructions from a remote user. Once installed on a computer, the malware creates a copy of itself in the Windows system folder and edits certain registry keys to ensure that it is run as a service when the system starts up.

Since the trojan was first discovered, AOL's AIM unit has been flooded with angry calls and emails from users who have had their accounts suspended and buddy lists wiped clean. AOL has requested that users whose accounts have been suspended contact the company's IM department for further instructions.

In the meantime, Graham Cluley of Sophos is urging companies to consider whether using IM is worth the risk of having corporate networks invaded.

"Fundamentally, many businesses will have to ask their staff if they really need IM for their day-to-day work, and if not, it may be more sensible to take it away," he told ComputerWorld. "We're certainly seeing more instant messaging malware being written, although they haven't yet had the same kind of impact as email-aware worms or Internet worms."

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Ukrainian Content Creators on Hook for Nearly $10M in Back Taxes

Content creators in Ukraine owe the equivalent of $9.3 million in back taxes, according to the country's State Tax Service.

Eroutique Relaunches Site Through YourPaysitePartner

Eroutique has relaunched its official website through YourPaysitePartner (YPP).

Update: Pornhub Will Not Block Ohio, Despite AV Law

Pornhub parent company Aylo will not block access to its websites in Ohio, despite new state age verification rules that came into effect Sept. 30.

Pineapple Support, Pornhub to Host 'ADHD-Friendly' Support Group

Pineapple Support and Pornhub are hosting a free online support group for performers with ADHD.

Judge Dismisses Some Claims in 'Children of Pornhub' Trafficking Suit

A United States district judge on Friday dismissed some but not all claims against Aylo in a long-running case involving CSAM allegations featured in the influential 2020 New York Times article “The Children of Pornhub.”

FSC Sets Key Dates, Qualifiers for December Board of Directors Election

The Free Speech Coalition (FSC) today announced key dates and qualifiers for its upcoming Board of Directors election.

RedGIFs Launches New 'Studio' Creator Platform

RedGIFs has launched its new Studio creator platform.

Arcom to Expand AV Enforcement to Smaller Adult Sites

The president of French media regulator Arcom revealed on Thursday that the agency plans to escalate its enforcement of age verification rules to include smaller adult sites, starting in late 2025 or early 2026.

AEBN Publishes Report on MILF, Cougar Trends

AEBN has published a report on MILF and Cougar categories from its straight theaters.

Pornhub to Shut Down Access in Arizona Over Age Verification

Aylo will geoblock Pornhub across Arizona starting Sept. 26, when the state’s age verification law, HB 2112, goes into effect.

Show More