facebook rss twitter

Twitter used as command channel for botnet

by Scott Bicheno on 14 August 2009, 14:05

Tags: Twitter

Quick Link: HEXUS.net/qatjh

Add to My Vault: x

Cruel irony

A blogger from Arbour Networks has uncovered a botnet that uses Twitter as its command and control structure.

"Basically what it does is use the status messages to send out new links to contact, then these contain new commands or executables to download and run. It's an infostealer operation," said Jose Nazario.

This discovery is especially poignant coming hot on the heels of Twitter being taken down by a presumed botnet controlled denial of service attack last week.

Nazario took a screenshot of an offending Twitter account and, referring to VirusTotal analysis, revealed that the original bot is detected by less than half of the antivirus tools under evaluation. The account has now been taken down by Twitter, but you can read more of Nazario's findings here.

 



HEXUS Forums :: 0 Comments

Login with Forum Account

Don't have an account? Register today!
Log in to be the first to comment!