Hackers Increasingly Using Twitter For Botnets
Trailrunner7 writes "Spammers aren't the only ones who have figured out that social networks like Twitter and Facebook are good for business. Sophisticated hackers conducting targeted attacks are also using the networks as a tool to manage malware installations on victims' networks.
Mandiant's latest "M-Trends" report, released on Thursday, says that the company has observed an increasing number of so-called "Advanced Persistent Threats" that are hijacking legitimate social networks and Web based services, including Facebook, Google Chat and MSN as command and control networks for malware installations. The revelation is part of a larger trend that saw sophisticated attacks on commercial entities outstrip attacks on the networks of government agencies and defense industry players, Mandiant reported."
I don't understand what the incentive is to stop using IRC for command and control.
Twitter is actually good for something after all
with how Twitter and various other social networks utilize hyperlinks. The problem is that most URLs are shortened in messages, so all person A has to do is tell person B something is going on, and click the link to find out more. Person A clicks link, silent download commences. It's circumstances like these where I wish URL shortening would just fall off the face of the earth. It just has such a high possibility of being exploited and there's no way to see where the shortened URL will go without using some script, it's just not that safe.
Gee George, deez hackers shore are sophistimacated!
You issue it a base64 encoded URL where to get more instructions. Then the attacker can use any website, google pages, etc to issue the command.
I followed one of them once, they usually added layers of abstraction to make it 'difficult' for a human to follow. Meaning one tweet, lead to another tweet, lead to another tweet, lead to a URL, which had another URL which then contained something like "ping whitehouse.gov"
Those hackers must be busy....
You issue [a] URL where to get more instructions. Then the attacker can use any website, google pages, etc to issue the command.
Yes you can. And this *isn't* hacking, cracking, or any hot sound-byte word.
If you want news from today, you have to come back tomorrow.
Command received. \/14gR4 ads transmitting now. Nigerian prince story queued.
Who would win this election: Andrew Weiner vs Andrew Weiner's weiner.
If a group of people play online on the same game and interact, then it's teamwork in some form. No matter what term you call it. If they want to take "Gangs" out of online games. Then take multiplayer out completely. As long as two people have the ability to be allies, there is going to be teams, as they put it, gangs.
I posted about this being the case way back (5 years ago?) when people were talking about IRC bots and CCs, but I got to say, it is impressive that now so many years later, people are catching up to this style of thinking, gives me hope for hackers out there..