Virus alert: Rbot sets your webcam to spy on you

Password-stealing, DDoS-launching virus sends footage of your home to virus writer

NEWS A new worm has been discovered in the wild that's not just settling for invading users' PCs - it wants to invade their homes too.

The Rbot-GR virus follows a fairly traditional malware route of exploiting Microsoft security vulnerabilities and installing a Trojan horse on infected machines. However, the worm also spies on users by taking control of their webcam and microphone, then sending images and soundtracks back to the hackers, according to antivirus firm Sophos.

As well as getting an insight into homes and businesses across the world, the worm also allows the malware writer to take a look at information on the infected machine's hard drive and to steal passwords, as well as launching denial-of-service attacks.

Graham Cluley, senior technology consultant at Sophos, said that the virus could be used for industrial espionage - or simply by a nosey hacker to take a look into people's bedrooms.

"Whether this worm is the work of professional snoopers or lusty teenagers - it's hard to say for certain. What we do know if that there have been a few hundred different versions of the Rbot worm, all of which have been designed to gain some kind of remote access to innocent users' data. This one goes further by also specifically collecting webcam footage," Cluley said. "It seems more and more hackers are building a cocktail of different functionality into their creations."

For those who have the virus, they may be unaware their every move could be being tracked by remote hackers. An infected webcam may show an "active light" when it's being used but for webcams without such light, there's no giveaway the hacker is watching.

There is, however, one simple way to dodge the prying eyes of the malware merchants - just unplug or switch the webcam off when it's not in use.

Comments

There are 3 comments. Join the discussion

  1. 1. Z D'WULF

    so where's the fix for this?

    you folks have really gotta stop with this "fox news" kind of scare journalism.

    all this lame article does is try to scare people and does nothing to educate the users on how to avoid or fix the problem, other than turn the camera off, which equates right up there with "the government is broken...so just ignore it."

    • 24 August 2004 20:50
    • Add comment
  2. 2. anonymous

    Hey i just bought a webcam ;-) When they capture this virusmaker they should spy him or her with a surveilance cam.

    • 25 August 2004 08:33
    • Add comment
  3. 3. User0n3

    i got it and i fixed it by shuting 135 137 139 445 tcp and udp ports with a firewall (even a free firewall can do it), stop NETBT service on windows for home pcs with single internet access, deleting every program i didn't know and which start with windows (thanks to the freeware "Starter"), and fixing windows with the last updates. From that time: no virus or trojan or backdoor on my pc !

    • 25 August 2004 12:31
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters