Hey guys how is everyone doing?,
Coming here to share a couple cool articles about a new type of malware that was getting intructions from Memes on Twitter, yes you read it right Memes.
Here is a little summary of the findings.
The malware itself is relatively underwhelming: like most primitive remote access trojans (RATs), the malware quietly infects a vulnerable computer, takes screenshots and pulls other data from the affected system and sends it back to the malwares command and control server.
Whats interesting is how the malware uses Twitter as an unwilling conduit in communicating with its malicious mothership.
Trend Micro said in a blog post that the malware listens for commands from a Twitter account run by the malware operator. The researchers found two tweets that used steganography to hide /print commands in the meme images, which told the malware to take a screenshot of an infected computer. The malware then separately obtains the address where its command and control server is located from a Pastebin post, which directs the malware where to send the screenshots
The malware appears to have first appeared in mid-October, according to a hash analysis by VirusTotal, around the time that the Pastebin post was first created.
But the researchers admit they dont have all the answers, and more work needs to be done to fully understand the malware. Its not clear where the malware came from, how it infects its victims or whos behind it. Its also not clear exactly what the malware is for or its intended use in the future. The researchers also dont know why the Pastebin post points to a local, non-internet address, suggesting it may be a proof-of-concept for future attacks.
Although Twitter didnt host any malicious content, nor could the tweets result in a malware infection, its an interesting (although not unique) way of using the social media site as a clever way of communicating with malware.
The logic goes that in using Twitter, the malware would connect to twitter.com, which is far less likely to be flagged or blocked by anti-malware software than a dodgy-looking server.
For more information you can read articles on the links below:
https://blog.trendmicro.com/trendlabs-security-intelligence/cybercriminals-use-malicious-memes-that-communicate-with-malware/https://techcrunch.com/2018/12/17/malware-commands-code-twitter-hidden-memes/Have a great week.
Cheers
This subject is very interesting.
It's hard to imagine that they managed to use Twitter Memes to attack users.
Security and privacy have to be taken very seriously.