UPDATED: In an advisory posted by enterprise IM vendor IMlogic Wednesday, officials warned of a new worm (define) spread by old means: getting users to click on a URL (define) that purports to come from a friend on their buddy list.
The latest threat to AOL's instant messaging (IM) platform, AIM, again targets users' penchants to blindly click on links supplied by friends. The Gpic.aol worm comes with a message saying, "damn this looks just like me lol" and a link to what is displayed as pictures.google.com.
In reality, the displayed URL obscures the real Web site at newpeople.no-ip.info, which then downloads onto the user's system, collects the names in the buddy list and sends the same message to all of them.
Gpic.aol is considered a medium-level risk threat; it doesn't actually deliver a payload that allows the malware (define) writer to gain remote access to the computer or corrupt or erase data on the hard drive.