In August 2009, Arbor Networks researcher Jose Nazario uncovered a botnet using Twitter as a command and control mechanism. Since then, other examples of attackers taking advantage of Web 2.0 sites have continued to sporadically pop up.
The tactic remains quite rare, but there are a number of reasons why attackers may increasingly look to such sites for hosting purposes.
“Attackers are taking advantage of the ability with these social networking platforms to hide their activities in plain site,” a spokesperson for EMC’s RSA security division told eWEEK. “Because of the millions of social networking users, cyber-criminals can simply blend their illegal activities and content and get lost in the crowd. And they can do so using encryption to cover their tracks.”
In a lengthy analysis, RSA’s FraudAction Research Lab examined how attackers used an unidentified social networking site to send commands to a Brazilian banker Trojan.
According to RSA, this is how it worked:
The method described above “allows the cyber-criminal to issue encrypted commands without renting a dedicated, bulletproof server or registering a domain for the malware’s communication points,” RSA researchers noted in the blog post.
“The infected PC would be communicating to an account that is hosted on a legitimate social network rather than with a botnet mother ship server,” the spokesperson continued. “Even if that social network account gets taken down, it’s still much faster and easier for the cyber-criminal to set up new accounts for free and evade detection of that account rather than having the botnet mother ship server end up on an IP address blacklist.”
The good news for users is that, once detected, the removal of this type of command and control points is relatively simple and quick.
Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…
Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…
Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…
Welcome to Silicon In Focus Podcast: Tech in 2025! Join Steven Webb, UK Chief Technology…
European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…
San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…