Spammers target IM accounts

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Growing incidents of spam attacks on some instant messaging networks are raising vexing questions about the future of one of the fastest-growing applications on the Internet. Unsolicited commercial appeals on instant messenger are still uncommon, but they are becoming prevalent enough that some IM fans worry their networks are vulnerable to the seemingly unstoppable marketing deluge that has long flooded email in-boxes. None of the major IM providers interviewed for this story would talk about their spam problems in detail. But consumers and spam experts said the phenomenon is growing, with no silver bullet in sight. "The spam problem is horrible," said Donna Hartfiel, a three-year user of AOL Time Warner's ICQ instant messenger and a self-described homemaker and PC geek. She said numerous complaints and countermeasures have so far failed to damper the flow. "I get between 10 and 30 spams each day, mostly to porn sites," Hartfiel said. "Some are very graphic (sexually explicit) messages." Spam schemes are not new to instant chat. Visitors to AOL Time Warner's proprietary chat rooms can expect their email in-box and computer screen to quickly crowd with unsolicited messages. Last year, peer-to-peer networks were scrutinised as potential vehicles for unsolicited commercial pitches via instant messenger. But at least two new applications illustrate a surge in the trend toward technologically sophisticated junk IM that could touch off the same sort of escalating arms race that's been under way for years in the realm of email. MassMess, launched two months ago by a 22-year-old St. Petersburg State University graduate and two friends, claims to have unleashed more than 10 million unsolicited commercial messages on Yahoo! Messenger users. Meanwhile, a steady barrage of spam on ICQ is popularly credited to a $99 shareware application, called ICQ Interest Search (ICQIS), sold on several different Web sites. "IM spam seems to be in its beginnings," said Jason Catlett, president of Junkbusters, an anti-spam organisation, and a visiting fellow at the Kennedy School of Government at Harvard University. "I've got a bad feeling about it because it looks a lot like junk email did in '95." Other spam-watchers concurred that junk IM is a nascent but growing menace. "I think it's very early days for IM spam," said David Ferris, an analyst with Ferris Research in San Francisco. "It will get much worse." IM vulnerable
Spammers have long considered email their preferred medium for a variety of reasons. It costs little or nothing to produce. Its processes are easily automated, and despite a growing array of defences aimed at shutting it out, delivery is all but guaranteed. Instant messenger may be just as susceptible to marketing come-ons, according to spam watchers. They say it offers sufficient convenience and vulnerability to raise the spectre of a major new front in the spam war. In addition, the popularity of instant chat has made IM services and their millions of users prime targets. According to research firm Jupiter Media Metrix, Yahoo! Messenger had 17.8 million unique US users in January 2002, up 57 percent from the previous year. Other services including MSN Messenger and AOL Instant Messenger also have been growing. ICQ Messenger was the only major service to register a decrease in users, according to Jupiter, falling to 8.4 million users last January from nine million users in January 2001. Instant messaging and email are distinguished primarily by IM's ability to detect whether someone else is online, a quality known as "presence." When people log onto an IM service, their user ID and IP (Internet Protocol) addresses -- a unique string of numbers that identifies someone's computer on the Internet -- are captured by a central server. This server essentially shares the information with everyone, allowing people to know who is online and to trade messages in real time. Messages are generally passed between IM users through a direct, client-to-client connection. Email messages, by contrast, are generally passed from a client to a server and subsequently downloaded to another client at the other end of the line. Along the way, email may pass through any number of servers. In theory, instant messaging offers the potential for stricter monitoring of abuse, since spammers currently must subscribe to the same service as their victims. IM services also typically offer a host of filtering options that can restrict messages to lists of pre-approved members, making it harder to pass through unsolicited messages. But IM spammers have found workarounds for at least some of these countermeasures, essentially mimicking widely used email spam techniques such as address "spoofing." Messages from MassMess, for example, appear to originate from the recipients themselves, making it harder to find and shut down the sender. ICQIS, meanwhile, uses anonymous servers to conceal the real source of its messages. In another trend that may provide new opportunities for IM spammers, the back-end differences that have so far served to distinguish email and instant messaging are steadily falling away. IM services such as Yahoo! and ICQ now allow people to send messages to recipients even when they are offline, much like email. The promise of interoperability between competing IM services could level the differences even further, introducing more server-to-server communication alongside the primary client-to-client connections. "It shouldn't be harder in theory to spam over IM than email," said Alex Diamandis, vice president of marketing for wireless IM start-up Odigo. From Russia, with spam
Several programmers are putting that thesis to the test, with mixed results so far. MessMass, a tiny mass-messaging firm based in Kupchino, Russia, has successfully targeted ICQ and Yahoo! Messenger users with an onslaught of commercial pitches. Advertising products and services ranging from pornography to casinos to financial schemes, MassMess charges $100 for a 300,000-message campaign (its most popular seller), and $300 for one million messages. For $650, customers can buy their own messaging utility, complete with a million-strong database of active users, and for $300 the company sells contact names that customers can use to create their own databases. The company culls its Yahoo! IDs from chat rooms and Yahoo! directories, among other sources. In an IM discussion, conducted under the pseudonym Elton Goston, an individual claiming credit as a MassMess founder said the company has pulled in several dozen paying customers so far. But Goston said the company has faced setbacks as well, having switched its primary to target to Yahoo! after ICQ engineers figured out how to shut down MassMess's access. AOL Time Warner acknowledged that it had disabled MassMess from connecting to ICQ users, but the company declined to say how. Goston -- whose primary Yahoo! Messenger account was disabled after CNET News.com queried the company about MassMess -- said his experiences so far have led him to conclusion that instant messaging may have inherent advantages at blocking the efforts of mass marketers over the long haul. "Some day it will be very hard to send messages in bulk," Goston wrote, adding that Yahoo! will act "not too fast, but someday it will definitely. Then we'll switch to emailing or whatever, maybe opt-in mailings. We've got some ideas." Yahoo would not comment directly on MassMess except to say that the service was apparently in violation of Yahoo's terms of service. The portal added that it could take action against individual spammers by shutting down their accounts. ICQ spam war
Although ICQ may have succeeded in deterring MassMess, spammers are lining up to zing the service with messages via ICQIS. ICQIS.com, registered to Ibragimov Ruslan in an undisclosed Russian location, has been unplugged. Ruslan did not respond to emailed queries. But existing copies of the site describe the tool in terms that make its purpose clear. "This tool allows you to send messages to thousands of online ICQ users," reads one copy. "Target audience may be filtered by their interest, country, city, occupation, age, gender, language. The best application for instant business -- site -- promotion. Messages are sending absolutely anonymously, hiding your real IP address." The tool has won raves from some of its corporate users. "I like the program so much, I am going to recommend it to all my friends seeking the same results I have gotten in the last 24 hours," according to one testimonial posted on the ICQIS Web site. "Your program has delivered as promised. It's simple and straight forward...From my point of view, this program is the best thing that ever happened to a new designer of Internet pages." Longtime ICQ users are less enthusiastic about ICQIS and have taken to the service's message boards to complain about the spam onslaught. AOL Time Warner said it has taken steps to counter IM spam, pointing to its ICQ anti-spam guidelines. Hartfiel, part of a group organizing to stem ICQ's spam glut, said the service had been responsive to tips she's sent in reporting the availability of ICQIS software; those pages have been pulled offline. But she said that ICQ's anti-spam tips have not proven effective. The most effective solution, to disable the feature that lets others know an ICQ user is online, cuts out too much of the service's functionality, she complained. Part of the problem may be that AOL Time Warner publishes the service's application programming interfaces in an attempt to encourage developers to build programs that interact with ICQ. While that may help software developers create applications that increase the service's popularity, it may also have the opposite effect by lending that same helping hand to spam toolmakers. Analysts said IM spam likely will be difficult to stamp out, especially as it takes root among overseas operators. MassMess "reminds me of (Sanford Wallace firm) Cyber Promotions establishing itself as a spam factory, which took about two years of litigation to shut down," said Junkbusters' Catlett. "And that was in Pennsylvania. This thing may be a difficult junk factory to stop."
For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section. Have your say instantly, and see what others have said. Go to the ZDNet news forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

23 minutes ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

28 minutes ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 hour ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 hour ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

2 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

2 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

2 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

5 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

6 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

6 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

8 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

9 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

10 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

18 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack
Random_Error

I think he's referring specifically to Android apps, as Apple do regulate their App Store, but Google seem to let any old crap onto the Android store!

1 day ago by Random_Error on RIM: BlackBerry will keep 'garbage' apps out of store
Paul Fezziwig

Keep the crap apps out?! How will they compete with Android and Apple's claim to fame of having so many life changing apps? I wonder if the media...

1 day ago by Paul Fezziwig via Facebook on RIM: BlackBerry will keep 'garbage' apps out of store
Aigars Mahinovs

It has been shown time after time that if there is an author store that sells the songs at even 1$ per song and gives you a high-quality digital...

1 day ago by Aigars Mahinovs via Facebook on Copyright isn't working, says European Commission
awbMaven

""As a result of Butyka's alleged conduct, researchers were unable to use the computers for more than two months while NASA removed the malicious...

1 day ago by awbMaven on US indicts Romanian over NASA climate change hack