Attackers Using Social Networks For Botnet Control
Trailrunner7 writes "Bot herders and the crimeware gangs behind banker Trojans have had a lot of success in the last few years with using bulletproof hosting providers as their main base of operations. But more and more, they're finding that social networks such as Twitter and Facebook are offering even more fertile and convenient grounds for controlling their malicious creations. New research from RSA shows that the gangs behind some of the targeted banker Trojans that are such a huge problem in some countries, especially Brazil and other South American nations, are moving quietly and quickly to using social networks as the command-and-control mechanisms for their malware. The company's anti-fraud researchers recently stumbled upon one such attack in progress and watched as it unfolded."
I was really starting to worry that these Command & Control things that use IRC chatrooms were going to ruin the good reputation that IRC has built up over the years.
I jokingly suggested something related before- create some software to have servers to join facebook, and those servers can answer stupid quizzes like "20 Ways to know if you're a Windows 2008 R2 server".
With status messages like:
ProcessingNode192 is bored (has nothing to do)...
StorageServer01 is feeling degraded (on array #2)...