Security researchers and vendors around the world are warning that a new version of the Shylock malware is hitting Skype users as Microsoft tries to migrate all Windows Live Messenger users to its VoIP platform.
Threatpost reports that the new form of Shylock malware has been detected in the UK, Europe and the US and comes with new features, such as the ability to send malicious links to the victim's contacts from the chat option.
The Trojan is specifically designed to steal financial information, such as login details for banking websites. Another new feature is that it can successfully perform code-injection attacks.
“The malware relies on a network of infected Web sites to perform drive-by download attacks. Once on the victim’s computer, it searches for and finds the Skype application. It then sends malicious links to the victim’s contacts via the chat service,” Threatpost reports.
According to security researchers at CSIS, the malware is based on a malicious plugin called “msg.gsm.” The malware allows sending messages and transferring files, even from Skype history, and can bypass security warnings when Skype tries to connect to other servers.
And finally, the updated version of Shylock can also be transmitted via network file shares and USB drives, which allows the attacker to perform a number of malicious actions on the infected computer, such as stealing cookies or downloading files and running them.
Security researchers have already started updating anti-viruses with the new definitions for this form of Shylock, so make sure your security software is up to date.

