Endpoint
8/14/2009
03:15 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%
Repost This

Twitter Used As Botnet Command Center

Researcher discovers first bot-herder using Twitter as its command-and-control hub, as well as Google's Jaiku microblogging service

Twitter has been spammed, DDoS'ed, and knocked offline, and now it has been used as the command center for a botnet.

A researcher yesterday looking for clues about the massive distributed denial-of-service (DDoS) attack on Twitter found a Twitter profile that was being used to send updates and malware to bots in an unrelated case of abuse of the site. "This is the first time I've seen in the wild botnet commands being pushed on Twitter -- it won't be the last," says Jose Nazario, manager of security research for Arbor, who first spotted the botnet's tweets. Nazario says there are probably other bot herders doing the same on Twitter.

"It looks like this guy is updating existing bots. I've seen and blogged malicious Twitter accounts in the past that spam links, using lures like 'follow this band!' that link to malcode," he says. But this is the first time Twitter has been used to send commands to bots, he says.

Nazario says Twitter has since disabled the profile, but he says the same user, "upda4t3," also has an account on Google's Jaiku, the search engine giant's microblogging service akin to Twitter. Joe Stewart, director of malware research for SecureWorks, in his Twitter update today said he had found "a newer version of the Twitter Bancos botnet -- this one uses another microblogging service as a backup C&C [command and control]."

Botnet operators are always looking for ways to more stealthily communicate and update their victimized machines -- some use peer-to-peer communications and HTTP to cover their tracks. Twitter is an ideal venue for them because it's flexible, noisy with all of its communiques, and doesn't have the anti-spam controls of other sites, Nazario says. And the anonymity of the URL shorteners also helps them send malicious links under cover, he says.

"They continue to innovate, and Twitter is likely to be yet another new channel to get updates out," he says.

So far, the botnet seems to be all about stealing online banking information from bank customers in Brazil: Nazario found a couple hundred bots based in Brazil, but he says it's difficult to get a real count. "To get that estimate, I went by who checked the update links on bit.ly [that] the bot was pushing via the Twitter updates," Nazario says. "The malware came from somewhere else -- we don't know yet where. The Twitter status updates contain links to new downloads, more malware, and stuff to update and evade AV detection."

Symantec researchers, meanwhile, are also dissecting the malware associated with the Twitter botnet. The Twitter status posts on the upda4t3 account were sending out new download links to malware that Symantec calls Downloader.Sninfs.

The downloader reads a specific Twitter RSS feed once, according to Symantec. "The RSS feed is simply a text file similar to other RSS feeds found on other Internet sites. The RSS text file contains information as to where Downloader.Sninfs can find additional threats to download onto the compromised system. In this way the RSS file acts like a config file for the malware," Symantec researcher Peter Coogan blogged.

The malware downloaded by the Trojan is an existing Bancos password-stealing Trojan, according to Symantec, that poses as the interface at some Brazilian banks in order to steal passwords and other data off the victim's computer.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Senior Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web