Endpoint

8/14/2009
03:15 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Twitter Used As Botnet Command Center

Researcher discovers first bot-herder using Twitter as its command-and-control hub, as well as Google's Jaiku microblogging service

Twitter has been spammed, DDoS'ed, and knocked offline, and now it has been used as the command center for a botnet.

A researcher yesterday looking for clues about the massive distributed denial-of-service (DDoS) attack on Twitter found a Twitter profile that was being used to send updates and malware to bots in an unrelated case of abuse of the site. "This is the first time I've seen in the wild botnet commands being pushed on Twitter -- it won't be the last," says Jose Nazario, manager of security research for Arbor, who first spotted the botnet's tweets. Nazario says there are probably other bot herders doing the same on Twitter.

"It looks like this guy is updating existing bots. I've seen and blogged malicious Twitter accounts in the past that spam links, using lures like 'follow this band!' that link to malcode," he says. But this is the first time Twitter has been used to send commands to bots, he says.

Nazario says Twitter has since disabled the profile, but he says the same user, "upda4t3," also has an account on Google's Jaiku, the search engine giant's microblogging service akin to Twitter. Joe Stewart, director of malware research for SecureWorks, in his Twitter update today said he had found "a newer version of the Twitter Bancos botnet -- this one uses another microblogging service as a backup C&C [command and control]."

Botnet operators are always looking for ways to more stealthily communicate and update their victimized machines -- some use peer-to-peer communications and HTTP to cover their tracks. Twitter is an ideal venue for them because it's flexible, noisy with all of its communiques, and doesn't have the anti-spam controls of other sites, Nazario says. And the anonymity of the URL shorteners also helps them send malicious links under cover, he says.

"They continue to innovate, and Twitter is likely to be yet another new channel to get updates out," he says.

So far, the botnet seems to be all about stealing online banking information from bank customers in Brazil: Nazario found a couple hundred bots based in Brazil, but he says it's difficult to get a real count. "To get that estimate, I went by who checked the update links on bit.ly [that] the bot was pushing via the Twitter updates," Nazario says. "The malware came from somewhere else -- we don't know yet where. The Twitter status updates contain links to new downloads, more malware, and stuff to update and evade AV detection."

Symantec researchers, meanwhile, are also dissecting the malware associated with the Twitter botnet. The Twitter status posts on the upda4t3 account were sending out new download links to malware that Symantec calls Downloader.Sninfs.

The downloader reads a specific Twitter RSS feed once, according to Symantec. "The RSS feed is simply a text file similar to other RSS feeds found on other Internet sites. The RSS text file contains information as to where Downloader.Sninfs can find additional threats to download onto the compromised system. In this way the RSS file acts like a config file for the malware," Symantec researcher Peter Coogan blogged.

The malware downloaded by the Trojan is an existing Bancos password-stealing Trojan, according to Symantec, that poses as the interface at some Brazilian banks in order to steal passwords and other data off the victim's computer.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11487
PUBLISHED: 2018-05-26
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
CVE-2018-11471
PUBLISHED: 2018-05-25
Cockpit 0.5.5 has XSS via a collection, form, or region.
CVE-2018-11472
PUBLISHED: 2018-05-25
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
CVE-2018-11473
PUBLISHED: 2018-05-25
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
CVE-2018-11474
PUBLISHED: 2018-05-25
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser.