Posted on Thursday, August 13th, 2009 | Bookmark on del.icio.us

Twitter-based Botnet Command Channel

by Jose Nazario

UPDATED TO ADD STATS AND JAIKU PROFILE AND A TUMBLR PROFILE

While digging around I found a botnet that uses Twitter as its command and control structure. Basically what it does is use the status messages to send out new links to contact, then these contain new commands or executables to download and run. It’s an infostealer operation.

The account in question is under analysis by Twitter’s security team. I spotted it because a bot uses the RSS feed to get the status updates.

upd4t3 twitter profile.png

As for the original bot in question that fetches the updates, here’s the VirusTotal analysis, where you can see it’s detected by 19/41 (46.34%) AV tools under evaluation. We can look at the status messages and discover more nefarious activity; the bot’s hiding new malcode which is poorly detected this way. The original link from the malcode came from a ShadowServer nightly link report, which they make available to folks. Many thanks to them.

Let’s look at one of the update messages; it’s pretty clearly base64 encoded. What does it say?

$ echo "aHR0cDovL2JpdC5seS9SNlNUViAgaHR0cDovL2JpdC5seS8yS29Ibw==" | openssl base64 -d
hxxp://bit.ly/R6STV hxxp://bit.ly/2KoHo

OK, a couple of links. One is dead (to a pastebin), one is live.

That second link yields a base64 encoded block of text. When we un-encode it using base64 we see a PKZIP archive (which we have dumped as “out.qqq” since we don’t know what the extension would have been beforehand). We can then unpack this and see what we find:

$ unzip out.qqq
Archive: out.qqq
inflating: gbpm.dll
inflating: gbpm.exe
$ openssl md5 gbpm.*
MD5(gbpm.dll)= ceb8d7fd74da0a187cc39ced4550ddb4
MD5(gbpm.exe)= a5cc8140e783190efb69d38c2be4393f

gbpm.dll is UPX packed, so we can unpack this:

$ upx2 -d gbpm.dll.upx
Ultimate Packer for eXecutables
Copyright (C) 1996,1997,1998,1999,2000,2001,2002,2003,2004,2005,2006
UPX 2.02 Markus Oberhumer, Laszlo Molnar & John Reiser Aug 13th 2006
.
File size Ratio Format Name
-------------------- ------ ----------- -----------
263680 <- 103424 39.22% win32/pe gbpm.dll.upx
.
Unpacked 1 file.

This file looks like an infostealer. Here are some of the URLs it will send data to:

hxxp://64.79.197.110/friends/alert/new.php
hxxps://www2.bancobrasil.com.br/aapf/login.jsp?aapf.IDH=sim
hxxp://64.79.197.110/friends/post.php
hxxps://www2.bancobrasil.com.br/aapf/
hxxps://www2.bancobrasil.com.br/aapf/

gbpm.exe is packed with a different packer.

That DLL is very poorly detected, the EXE has a VTotal result of 9/41 (21.95%) and appears to be a Buzus sample according to one vendor.

The account is presently live but under review by Twitter, and is just one of what appear to be a handful of Twitter C&C accounts.

UPDATE 14 Aug 2009

Via bit.ly, some statistics that suggest the malcode has infected a couple hundred PCs, mostly in Brazil.

bitly twitter botnet geo.png

Now that it’s disabled, “upd4t3″ had a similar profile on Jaiku.com:

upd4t3 jaiku profile.png

Many thanks to the Jaiku team for reviewing and shutting this account down. Still looking for more services “upd4t3″ is abusing … looks like Tumblr has also been used by “upd4t3″:

upd4t3 tumblr profile.png

Still poking around various micro-blogging services. I wonder why he abandoned Tumblr. (There are more microblogging tools than I had anticipated …)

Share

113 Responses | Add your own



Comment Post by: Guilherme Venere — August 13th, 2009 @ 3:26 pm EST  Reply

Nice post Jose!

the URL hxxps://www2.bancobrasil.com.br/aapf/login.jsp?aapf.IDH=sim is from a Brazilian bank login page. This may be a banker and oh, surprise, may have Brazilian hackers involved :)

Comment Post by: securitybananas.com » Twitter based botnet — August 13th, 2009 @ 4:16 pm EST  Reply

[...] http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/ Comments are off for this post Digg this [...]

Comment Post by: Keith — August 13th, 2009 @ 4:53 pm EST  Reply

Nice find. I hate to admit but this is really an innovative control. BTW, account is now suspended

Comment Post by: FT.com | Tech Blog | Hackers use Twitter to control botnets — August 13th, 2009 @ 6:19 pm EST  Reply

[...] researcher Jose Nazario of Arbor Networks said Thursday he had found a handful of streams on the micro-blogging service that were used to tell drone computers where to go to download new [...]

Comment Post by: C’est la rentrée – attaques DDoS sur Twitter ? « Criminalités numériques — August 13th, 2009 @ 6:23 pm EST  Reply

[...] Information incidente révélée aujourd’hui par Jose Nazario de chez Arbor Networks (origine ici). Celui-ci a découvert pendant des investigations sur cette affaire d’attaque en déni de [...]

Comment Post by: tech: Twitter-based Botnet Command Channel (Jose Nazario/Arbor Networks Security) | tech3bite — August 13th, 2009 @ 7:34 pm EST  Reply

[...] Nazario / Arbor Networks Security: Twitter-based Botnet Command Channel  —  While digging around I found a botnet that uses Twitter as its command and [...]

Comment Post by: Tom — August 13th, 2009 @ 8:57 pm EST  Reply

Ironically, PoC code was released several months ago which did just this. The code was updated for a talk at DEFCON 17 this year which does…base64 encoded commands. You can download the code and more information here: http://www.digininja.org/projects/kreiosc2.php

Comment Post by: links for 2009-08-13 (Jarrett House North) — August 13th, 2009 @ 10:01 pm EST  Reply

[...] Twitter-based Botnet Command Channel (Security to the Core | Arbor Networks Security) Nasty nasty nasty. Using base64 encoded tweets, that translate to tinyURLs, that download as zipped archives, that unpack with malicious payloads. (tags: twitter security) [...]

Comment Post by: BotNet command and control finds new home on Twitter — August 13th, 2009 @ 11:18 pm EST  Reply

[...] Source: Arbor Networks :: Twitter-based Botnet Command Channel [...]

Comment Post by: Robert Peaslee — August 13th, 2009 @ 11:35 pm EST  Reply

I wonder why he wasn’t using a symmetric encryption algorithm for encrypting the urls instead of just encoding them base64? He could have kept that pretty well secret with just a little thought.

Comment Post by: Twitter-based Botnet Command Channel | Twittermazing — August 13th, 2009 @ 11:46 pm EST  Reply

[...] Twitter-based Botnet Command Channel Raj’s shared items in Google Reader While digging around I found a botnet that uses Twitter as its command and control structure. Read More [...]

Comment Post by: Old News: Twitter can be used for Botnet Command & Control — spylogic.net — August 13th, 2009 @ 11:51 pm EST  Reply

[...] but true…today a researcher discovered that Twitter has been used for command and control of a botnet which may have been used by Brazilian hackers to steal online banking login information.  Kudos to [...]

Comment Post by: Social Media Security » Old News: Twitter can be used for Botnet Command & Control — August 14th, 2009 @ 12:12 am EST  Reply

[...] but true…today a researcher discovered that Twitter has been used for command and control of a botnet which may have been used by Brazilian hackers to steal online banking login information.  Kudos to [...]

Comment Post by: John Reedaw — August 14th, 2009 @ 3:09 am EST  Reply

Nice pick up, José!! It’s always very interesting to follow your posts.

Comment Post by: meneame.net — August 14th, 2009 @ 5:27 am EST  Reply

Controlando botnets a través de Twitter…

[ENG] José Nazario de Arbor Networks ha descubierto el uso de Twitter para controlar botnets: "El usuario utilizaba los mensajes para enviar nuevos enlaces a sus contactos, enlaces que contenían nuevos comandos o programas para descargar y ejecuta…

Comment Post by: Twitter used to manage botnet, says security expert | O24int — August 14th, 2009 @ 6:51 am EST  Reply

[...] on infected machines, wrote Jose Nazario, manager of security research at Arbor Networks, on in a blog posting on [...]

Comment Post by: Novo ataque visa o Twitter » SegBlog — August 14th, 2009 @ 8:47 am EST  Reply

[...] ataque visa o Twitter Ontem foi descoberta pelo Jose Nazario da Arbor Networks a atividade de uma botnet que utiliza Twitter para enviar informações sobre [...]

Comment Post by: تويتر يستخدم في التحكم في شبكة البوت نت | تيدوز — August 14th, 2009 @ 9:07 am EST  Reply

[...] ARBOR – [...]

Comment Post by: Twitter botnet plundert bankrekeningen - BLOG PC Web plus - — August 14th, 2009 @ 9:29 am EST  Reply

[...] uploadt. In Brazilië gebruiken de meeste banken nog steeds een gebruikersnaam en wachtwoord. De Twitter bot kwam aan het licht omdat het de RSS feed gebruikt om status updates te krijgen. Het account in [...]

Comment Post by: Angelo Dell'Aera — August 14th, 2009 @ 9:47 am EST  Reply

Nice post Jose. I was just thinking about how simple it could be to raise the bar through a photography fanatic blog and just a bit of steganography…

Comment Post by: links for 2009-08-14 | Yostivanich.com — August 14th, 2009 @ 10:04 am EST  Reply

[...] » Twitter-based Botnet Command Channel · Security to the Core | Arbor Networks Security Makes it easy to avoid getting an IP Address block. (tags: twitter cracking security botnet) [...]

Comment Post by: Shlok Vaidya’s Thinking » Botnet Command Via Twitter — August 14th, 2009 @ 10:18 am EST  Reply

[...] Vaidya’s Thinking While digging around I found a botnet that uses Twitter as its command and control structure. Basica… Subscribe to comments Comment | Trackback | Tags: gaming [...]

Comment Post by: Allan Rowntree — August 14th, 2009 @ 10:33 am EST  Reply

Not to be confused with:

#mmjChallenge[CqPSy8qqd7IW4POiaRAwbjyMmtYRrGdi]

Tweets my new games uses as a way of passing challenges from player to player!

Check out http://mmj.arowx.com for latest details, it’s coming soon!

Comment Post by: Hackers utilizan Twitter para controlar redes de bots | ALT1040 (Internet) — August 14th, 2009 @ 10:41 am EST  Reply

[...] etc. Más tarde evolucionaron a otros sistemas de control como redes P2P pero ahora todo cambió y el uso de las redes sociales puede ser el próximo [...]

Comment Post by: Hackers utilizan Twitter para controlar redes de bots | Moova! News on the Move — August 14th, 2009 @ 11:48 am EST  Reply

[...] etc. Más tarde evolucionaron a otros sistemas de control como redes P2P pero ahora todo cambió y el uso de las redes sociales puede ser el próximo [...]

Comment Post by: Usan Twitter Para Controlar Red Zombie. - La Comunidad DragonJAR — August 14th, 2009 @ 12:01 pm EST  Reply

[...] [...]

Comment Post by: Federico Ch. Tomasczik (ftomasczik) 's status on Friday, 14-Aug-09 17:24:13 UTC - Identi.ca — August 14th, 2009 @ 1:24 pm EST  Reply

[...] Lo nuevo en bicharracos… Twitter-based Botnet Command Channel http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/ [...]

Comment Post by: Twitter used to manage botnet, says security expert — August 14th, 2009 @ 1:40 pm EST  Reply

[...] on infected machines, wrote Jose Nazario, manager of security research at Arbor Networks, on in a blog posting on [...]

Comment Post by: Botnets ontdekken Twitter | Techfreak — August 14th, 2009 @ 2:22 pm EST  Reply

[...] Nazario, hoofd secu­rity research bij Arbor Net­works, kwam de bot­ne­tac­tiviteit via Twit­ter op het spoor door­dat de bots via de rss-feed van het [...]

Comment Post by: Interesting Information Security Bits for 08/14/2009 | Infosec Ramblings — August 14th, 2009 @ 4:25 pm EST  Reply

[...] is interesting. A botnet being controlled via Twitter. >> Twitter-based Botnet Command Channel * Security to the Core | Arbor Networks Security Tags: ( twitter botnet [...]

Comment Post by: Jesper Wallin — August 14th, 2009 @ 4:32 pm EST  Reply

Hehe, pretty smart if you ask me.. Thank god it’s easy for Twitter to kill these “channels” as well as see who’s requesting these tweets (finding what machines/networks are infected) .. :-)

Comment Post by: Malware, del IRC a Twitter — August 14th, 2009 @ 5:27 pm EST  Reply

[...] Vía Twitter-based Botnet Command Channel [...]

Comment Post by: Botnetz nutzt Twitterupdates von upd4t3 | elexpress.de — August 14th, 2009 @ 5:48 pm EST  Reply

[...] sicherlich nicht nur bei Nutzern angekommen, die den Dienst als solches im gutem Sinne nutzen. Laut Jose Nazario von Arbor hat ein Botnetz die neuen Befehle für die Zombirechner über Twitter und anderen Diensten [...]

Comment Post by: Twitter utilisé par un Botnet ! « — August 14th, 2009 @ 6:02 pm EST  Reply

[...] Nazario d’Arbornetworks.com, a découvert un botnet qui utiliserait Twitter, le site de réseau social et de [...]

Comment Post by: Security firms discover botnet on Twitter - Programming Blog — August 14th, 2009 @ 7:50 pm EST  Reply

[...] be used as the command center for harnessing a “botnet” of virus-infected computers, security firms Arbor Networks and Symantec reported. In a blog post Friday, Symantec analyst Peter Coogan wrote that researchers [...]

Comment Post by: Freetracking.org » Security firms discover botnet on Twitter — August 14th, 2009 @ 11:09 pm EST  Reply

[...] be used as the command center for harnessing a “botnet” of virus-infected computers, security firms Arbor Networks and Symantec reported. In a blog post Friday, Symantec analyst Peter Coogan wrote that researchers [...]

Comment Post by: “Zombies” über Twitter steuerbar « infoblog.li — August 15th, 2009 @ 6:23 am EST  Reply

[...] ermöglicht, die so weitere Anweisungen bekommen. Diese graviernde Sicherheitslücke wurde von Arbor Networks entdeckt. Bei Twitter ist dieses Problem bereits bekannt und es wurden inzwischen auch betroffene [...]

Comment Post by: Botnet on Twitter Now! « TheTechJournal.com — August 15th, 2009 @ 7:33 am EST  Reply

[...] Security holes of Twitter has been exposed here again. An employee of Arbor Networks has recently discovered a botnet that uses Twitter as its command and control structure. The Twitter user “upd4t3″ has been operating an infostealer operation using his account. The user posts status updates with links which contains commands or executables to download and run. The process is described at Arbor Networks blog. [...]

Comment Post by: Twitter was Dwelling Botnets under the Hood - Home for DDoS | Taranfx: Technology Blog — August 15th, 2009 @ 1:14 pm EST  Reply

[...] The traditional way of managing botnets was IRC or different honeypots.  But with changing times,  botnet owners are continuously working on finding new ways of keeping their networks up and running, and Twitter seems to be the latest trend among the tricks. Twitter came to know about this from an account that it recently suspended. What was it doing?  It was being used to post tweets that had links to “commands or executables” to download and run, which would then be used by the botnet code on infected machines. “I spotted it because a bot uses the RSS feed to get the status updates, the account, called “Upd4t3″, is under investigation by Twitter’s security team, according to Nazario. But the account is just one of what appear to be a handful of Twitter command and control accounts,” Nazario, a security researcher, wrote. [...]

Comment Post by: Το Twitter χρησιμοποιήθηκε για την καθοδήγηση botnet | TechTips Blog - Τεχνολογικά Νέα - Ειδήσεις - Βοηθήματα — August 15th, 2009 @ 2:12 pm EST  Reply

[...] στην εταιρεία δικτυακής ασφαλείας Arbor Networks, έγραψε στο blog της εταιρείας ότι το Twitter χρησιμοποιήθηκε για την καθοδήγηση [...]

Comment Post by: Geek Montage » Botnet Using Twitter — August 15th, 2009 @ 3:13 pm EST  Reply

[...] and that they’re only limited by the creator’s creativity. The article can be read here, but I’ll provide an excerpt for those who have only of the slighest interest and not enough [...]

Comment Post by: DarkKnightH20 — August 15th, 2009 @ 3:37 pm EST  Reply

Very interesting. I’m posting an excerpt on http://www.geekmontage.com if you don’t mind (with a link back to here of course). Still, this isn’t too surprising considering that their niche, IRC servers, have been easily compromised time after time. Creativity is the only thing limiting communication between a botnet owner and his/her bots.

Comment Post by: Faisal Khan — August 15th, 2009 @ 6:28 pm EST  Reply

Jose, great analysis…. how can Twitter play a role in this – to stop its network from being used as a Command center??? With 10,000s of signups a day and million of messages, surely, this new medium can be termed even more threatening.

Comment Post by: BelchSpeak » Post Topic » Twitter Bot Master — August 16th, 2009 @ 12:43 am EST  Reply

[...] zombies only had to follow the account using an RSS feed subscription. You can read all about it at Arbors blog here. I see no reason why this method wouldn’t with other public posting methods such as [...]

Comment Post by: Twitter now being used to direct botnets | Cool Stuff for the Mac Pro. — August 16th, 2009 @ 1:02 am EST  Reply

[...] Twitter? Twitter! TWITTER! Yes, the world’s most important Web site has been co-opted by evildoers, being used to control personal information-stealing [...]

Comment Post by: Twitter vira central de controle para botnet « 1security’s Blog — August 16th, 2009 @ 5:54 am EST  Reply

[...] especialista afirmou no blog da empresa que uma conta no microblog era responsável por enviar códigos aos computadores, transformando-o [...]

Comment Post by: infinity's status on Sunday, 16-Aug-09 09:55:58 UTC - Identi.ca — August 16th, 2009 @ 5:56 am EST  Reply
Comment Post by: Brazen Botnet Uses Twitter Comm Channel - Lets Be Secure | Lets Be Secure — August 16th, 2009 @ 7:08 am EST  Reply

[...] links to contact, then these contain new commands or executables to download and run," Nazario said in a blog post. "It’s an infostealer [...]

Comment Post by: Twitter can be used to steal you bank account details — August 16th, 2009 @ 8:29 am EST  Reply

[...] week, since Twitter was first attacked and it still seems to be reeling from it. Now a researcher, Jose Nazario, has discovered that an account in Twitter is being used as a Botnet, for its command and control [...]

Comment Post by: וירוס השתמש בחשבון טוויטר כדי להעביר הוראות למחשבים נגועים | Newsgeek — August 16th, 2009 @ 12:46 pm EST  Reply

[...] סוף השבוע הודיעה חברת אבטחת המידע Arbor Networks כי מצאה חשבון משתמש בטוויטר, אשר בו מתבצע שימוש לצורך [...]

Comment Post by: GeekDays » Hackers utilizan Twitter para controlar redes de bots — August 16th, 2009 @ 3:04 pm EST  Reply

[...] etc. Más tarde evolucionaron a otros sistemas de control como redes P2P pero ahora todo cambió y el uso de las redes sociales puede ser el próximo [...]

Comment Post by: slacker2d (slacker2d) 's status on Sunday, 16-Aug-09 22:35:14 UTC - Identi.ca — August 16th, 2009 @ 6:35 pm EST  Reply

[...] twitter based #botnet command channel http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/ [...]

Comment Post by: duritong's status on Sunday, 16-Aug-09 22:39:01 UTC - Identi.ca — August 16th, 2009 @ 6:39 pm EST  Reply

[...] RT @slacker2d twitter based #botnet command channel http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/ [...]

Comment Post by: Not just Twitter, Jaiku too (Banker Trojan) | Virus Experts - We Make Your Digital Life Secured — August 16th, 2009 @ 6:40 pm EST  Reply

[...] Networks reported that malware (which we detect as Trojan-Banker.Win32.Banker.alwa and [...]

Comment Post by: Twitter down on Saturday, external apps to be affected | KBBS @ TECHBLOG — August 16th, 2009 @ 8:47 pm EST  Reply

[...] operation,” wrote Jose Nazario, manager of security research at Arbor Networks, on in a blog posting on [...]

Comment Post by: A Closer Look at the Twitter-Controlled Botnet (Part 1) « my 20% — August 16th, 2009 @ 11:47 pm EST  Reply

[...] I wasn’t aware of Jose Nazario’s post concerning this topic while I was conducting this research; I had only been exposed to the Wired [...]

Comment Post by: ID Brasileiros No Twitter Usados Em Botnet | Blog KTecNet — August 17th, 2009 @ 11:47 am EST  Reply

[...] como se parece uma conta destas (via Arbor Networks blog) [...]

Comment Post by: Malware y botnet a través de Twitter | Shadow Security — August 17th, 2009 @ 12:05 pm EST  Reply

[...] Kaspersky Lab y Jose Nazario publican una entrada en su blog en donde muestran capturas y más información sobre este malware que [...]

Comment Post by: A Closer Look at the Twitter-Controlled Botnet « Miscellaneous Security — August 17th, 2009 @ 12:56 pm EST  Reply

[...] wasn’t aware of Jose Nazario’s post concerning this topic while I was conducting this research; I had only been exposed to the Wired [...]

Comment Post by: Botnet que utiliza twitter como command & control | — August 17th, 2009 @ 11:09 pm EST  Reply

[...] del CSIRT-Antel de Uruguay me enteré que la gente de Arbor Networks (Jose Nazario) encontró una botnet que utiliza twitter como command & control. Es un cambio interesante en el comportamiento de las [...]

Comment Post by: Links of the Week: Data Security Edition | EPC's Computer Recyling Blog — August 18th, 2009 @ 10:49 am EST  Reply

[...] Twitter used to control botnet It was a matter of time, but Jose Nazario of Arbor Networks discovered a botnet that used Twitter for its command and control infastructure. While the account in question is obviously not a person, how long before a botnet writer creates an account that looks legitimate at first glance? [...]

Comment Post by: Hackers Use Twitter To Control Botnet | HackTalk — August 18th, 2009 @ 12:27 pm EST  Reply

[...] Network’s Jose Nazario, an expert on botnets, discovered the so-called command-and-control structure. Infected computers were following the [...]

Comment Post by: Marcosof Informatica y Telecomunicaciones » Blog Archive » Malware y botnet a través de Twitter — August 18th, 2009 @ 12:30 pm EST  Reply

[...] Kaspersky Lab y Jose Nazario publican una entrada en su blog en donde muestran capturas y más información sobre este malware que [...]

Comment Post by: The Linux Mint Blog » Blog Archive » The Mint Newsletter - issue 91 — August 19th, 2009 @ 7:01 am EST  Reply

[...] Botnet Command [...]

Comment Post by: YJ — August 19th, 2009 @ 9:05 pm EST  Reply
Comment Post by: Hilda Jones — August 20th, 2009 @ 2:13 pm EST  Reply

the base64 is the part that always makes me mad… great post

Comment Post by: Security and Social Media | Z0nbi — August 20th, 2009 @ 4:08 pm EST  Reply

[...] Being used as a C&C server to botnets [...]

Comment Post by: Uso estúpido de Twitter de la semana: dirigir una red de bots (botnet) » Consultorio del Dr. Ogalinski — August 20th, 2009 @ 10:29 pm EST  Reply

[...] Fuente: PC World, Arbor SERT [...]

Comment Post by: Support Wars » Brazen botnet uses Twitter comm channel — August 21st, 2009 @ 1:07 pm EST  Reply

[...] to contact, then these contain new commands or executables to download and run,” Nazario said in a blog post. “It’s an infostealer [...]

Comment Post by: Răufăcătorii secolului XXI « dreptungeek — August 24th, 2009 @ 12:33 pm EST  Reply

[...] că există un nou mod în care idila cu mesajele de 140 de caractere poate fi brutal întreruptă: un cont folosit de un bot pentru a infecta alte conturi. Între astfel de cazuri şi link-uri mascate, destule persoane neatente vor mai avea în viitor [...]

Comment Post by: Social Media Security Podcast » Social Media Security Podcast 1 – Social Zombies, Bad Facebook Apps, Twitter SPAM — August 25th, 2009 @ 11:15 am EST  Reply

[...] Twitter Botnet Found [...]

Comment Post by: Twitter as a botnet command center - Hack a Day — August 26th, 2009 @ 2:38 pm EST  Reply

[...] folks over at Arbor Networks were browsing Twitter and discovered something very strange: a Twitter account seemingly posting [...]

Comment Post by: Herb — August 26th, 2009 @ 5:25 pm EST  Reply

Seem like there is another out there now.

http://twitter.com/botn3tcontrol

Comment Post by: Често задавани въпроси » Blog Archive » twitter като средство за управление на ботнет — August 27th, 2009 @ 1:11 am EST  Reply

[...] за управление на ботнет August 27th, 2009 от singu От Arbor са разпознали ботнет, чийто пастир използва twitter за да [...]

Comment Post by: Blight Watch » Blog Archive » Botnet Using Twitter For Command/Control — August 27th, 2009 @ 4:57 am EST  Reply

[...] you’re interested in the full technical details, check out the Arbor Networks blog which found the problem in the first place, and which fully explores exactly how the [...]

Comment Post by: Jose Nazario — August 27th, 2009 @ 9:33 am EST  Reply

thanks, herb! i contacted twitter and the account was disabled overnight.

Comment Post by: TheTechJournal.com » Blog Archive » Botnet on Twitter Now! — August 31st, 2009 @ 5:33 am EST  Reply

[...] Security holes of Twitter has been exposed here again. An employee of Arbor Networks has recently discovered a botnet that uses Twitter as its command and control structure. The Twitter user “upd4t3″ has been operating an infostealer operation using his account. The user posts status updates with links which contains commands or executables to download and run. The process is described at Arbor Networks blog. [...]

Comment Post by: Wilhelm Greiners Communitainment-Blog » Blog Archive » Symantec warnt vor Kriminellen in Social Networks — August 31st, 2009 @ 2:00 pm EST  Reply

[...] missbraucht worden. Der von Symantec in der Pressemitteilung nicht genannte Dienst ist Twitter, wie Arbor Networks meldete: Brasilianische Cyber-Kriminelle hatten den Micro-Blogging-Dienst zur Steuerung ihrer Zombies [...]

Comment Post by: Security Justice » Blog Archive » Security Justice – Episode 16 DEFCON Recovery with @dave_rel1k — September 1st, 2009 @ 10:07 pm EST  Reply

[...] Twitter botnet? We told you so… [...]

Comment Post by: An Innovative Control – Twitter Being Used As Botnet Command Channel | the dancing packet — September 4th, 2009 @ 6:20 pm EST  Reply

[...] Twitter-based Botnet Command Channel [...]

Comment Post by: Trojan Hides Its Brain in Google Groups « Friendly Computers Virus Alerts — September 11th, 2009 @ 5:23 pm EST  Reply

[...] in touch with hacked PCs and update their malicious software. Researchers have also seen criminals hide their messages in RSS feeds that are set up to broadcast Twitter messages, said Gerry Egan, a director with [...]

Comment Post by: Trojan hides its brain in Google Groups | Sync-Tech - Syncing tomorrow with today. — September 11th, 2009 @ 8:50 pm EST  Reply

[...] in touch with hacked PCs and update their malicious software. Researchers have also seen criminals hide their messages in RSS feeds that are set up to broadcast Twitter messages, said Gerry Egan, a director with [...]

Comment Post by: Trojan Hides in Google Group « AKS-Feel The Change! — September 12th, 2009 @ 2:35 am EST  Reply

[...] to keep in touch with hacked PCs and update their malicious software. Researchers have also seen criminals hide their messages in RSS feeds that are set up to broadcast Twitter messages, said Gerry Egan, a director with [...]

Comment Post by: Trojan Hides Its Brain in Google Groups (PC World) | Breaking News Fast — September 12th, 2009 @ 4:40 am EST  Reply

[...] in touch with hacked PCs and update their malicious software. Researchers have also seen criminals hide their messages in RSS feeds that are set up to broadcast Twitter messages, said Gerry Egan, a director with [...]

Comment Post by: Rhialto — September 12th, 2009 @ 8:40 am EST  Reply

Interesting. But can you please separate the trackbacks from the real comments, since they are extremely irritating when you’re trying to read real comments from real people…

Comment Post by: Trojan hides its brain in Google Groups « I.T News & Stuff — September 14th, 2009 @ 1:30 am EST  Reply

[...] have also seen criminals hide their messages in RSS feeds that are set up to broadcast Twitter messages, said Gerry Egan, a director with [...]

Comment Post by: Un malware coordonné par un groupe de discussions Google « Service de Fax par Internet : Le Blog de TooFAX® — September 17th, 2009 @ 11:03 am EST  Reply

[...] pirates : plusieurs chevaux de Troie sont désormais contrôlés à travers des structures C&C hébergées sur Twitter. Le but recherché est d’entraver au maximum l’action des forces de l’ordre : d’une part, [...]

Comment Post by: Ботнеты: игра в прятки на Web 2.0 | ДайСлово! — September 21st, 2009 @ 4:53 am EST  Reply

[...] середине Устя эксперты Arbor Networks обнаружили в микроблогах Twitter в некоторой степени аккаунтов, с [...]

Comment Post by: Twitter-based Botnet Command Channel « "The CTI Blog" – A Daily View into the World of Cyber Threat Intelligence — September 29th, 2009 @ 12:01 pm EST  Reply

[...] Botnet Command Channel By pmakohon Twitter-based Botnet Command Channel: [...]

Comment Post by: A Closer Look at the Twitter-Controlled Botnet – Miscellaneous Security — October 11th, 2009 @ 7:58 pm EST  Reply

[...] wasn’t aware of Jose Nazario’s post concerning this topic while I was conducting this research; I had only been exposed to the Wired [...]

Comment Post by: Ботнеты: игра в прятки на Web 2.0 | Hacker Info — October 17th, 2009 @ 8:09 pm EST  Reply

[...] середине августа эксперты Arbor Networks обнаружили в микроблогах Twitter несколько аккаунтов, с которых [...]

Comment Post by: Twitter Turned Botherder – Security Threat Research News — December 12th, 2009 @ 8:08 am EST  Reply

[...] For more details, you can also check the original post from Arbor Sert. [...]

Comment Post by: 2010 – Year of the Zombie Cloud? » CounterMeasures — December 15th, 2009 @ 6:11 am EST  Reply

[...] page in spam campaigns, to attempt to overcome URL filtering in email messages. In recent months Twitter, Facebook, Pastebin, Google Groups and a Google AppEngine have all been used as surrogate Command [...]

Comment Post by: 2010 – Year Of The Zombie Cloud? | Business Computing World — December 16th, 2009 @ 5:43 am EST  Reply

[...] page in spam campaigns, to attempt to overcome URL filtering in email messages. In recent months Twitter, Facebook, Pastebin, Google Groups and a Google AppEngine have all been used as surrogate Command [...]

Comment Post by: Twitter as a botnet command center | Hack a Day Thailand — January 1st, 2010 @ 9:45 pm EST  Reply

[...] folks over at Arbor Networks were browsing Twitter and discovered something very strange: a Twitter account seemingly posting [...]

Comment Post by: Notes from a wireframe world » Blog Archive » Is cloud computing safe? Not if you’ve got data worth stealing. — April 8th, 2010 @ 11:41 am EST  Reply

[...] 2009 cybercriminals continued demonstrating their interest in abusing legitimate services such as Twitter, Google Groups, Facebook as command and control servers, as well as Amazon’s EC2 as a [...]

Comment Post by: Social Networks being used by Banking Trojans | Helablog — July 20th, 2010 @ 1:05 pm EST  Reply

[...] exploited as a command and control point belonging to a Trojan’s operation reportedly involves Twitter’s RSS feed option. The bot herder’s method of operation in this case is as [...]

Comment Post by: The Italian Honey Project » Social networks used as C&C server – Facebook? — July 22nd, 2010 @ 3:21 am EST  Reply

[...] google groups and twitter , here is another example about how a social network  (probably Facebook)  is being (mis)used by [...]

Comment Post by: DNS Botnet Cyberwar — July 22nd, 2010 @ 12:18 pm EST  Reply

[...] Transfer Protocol) como por ejemplo Twitter (Para más información puede leer el siguiente enlace :http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/). Una vez se consigue infectar con Malware y estos comienzan a acceder al canal de control, quedan [...]

Comment Post by: DNS BOTNET CYBERWAR « SR HADDEN SECURITY CONSULTING — July 23rd, 2010 @ 9:52 am EST  Reply

[...] Transfer Protocol) como por ejemplo Twitter (Para más información puede leer el siguiente enlace :http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/). Una vez se consigue infectar con Malware y estos comienzan a acceder al canal de control, quedan [...]

Comment Post by: Uncrackable DIY Pencil-and-Paper Encryption — August 5th, 2010 @ 5:29 pm EST  Reply

[...] cellphone create the modern day equivalent of a number station. In fact, there is at least one known bot net coordinated via an anonymous Twitter account (not encrypted, [...]

Comment Post by: על בוטנטים (Botnets), מלחמה טכנולוגית, IRC ושטויות נוספות. | טכנולוגיה ואבטחת מידע מזווית אחרת — August 10th, 2010 @ 10:51 pm EST  Reply

[...] הבוטנטים יתחברו לשרת (ראו "טופולוגיית בוטנטים" להלן), ממנו הם יקבלו את הפקודות. השרת יכול להיות בוטנט אחר, או "מפקדה" – בסיס מרכזי אליו מתחברים הבוטנטים. מקומות נפוצים להקמת מפקדה הם שרתי IRC, עליהם דיברנו כבר בעבר, תוכנות מסרים מידיים (כן כן!) ואפילו אתרי אינטרנט, כמו טוויטר! [...]

Comment Post by: Antivirus — August 22nd, 2010 @ 10:46 pm EST  Reply

This is very nice post about twitter botnet. I saw a video on youtube how people can command twitter using botnet to do something they want based on what they command it to do.

Comment Post by: Botnets : Aeterna's World — September 21st, 2010 @ 5:10 pm EST  Reply

[...] launch of twitter several have switched from the traditional IRC channels(Chat software) to using twitter to regulate themselves. Now I think it’s quite an interesting and cool way of controlling the [...]

Comment Post by: Who Do You Know? | Morpho Designs — December 10th, 2010 @ 8:39 pm EST  Reply

[...] is, by and large, ethically neutral. The most benign tool becomes a weapon of mass destruction in the hands of a spammer or so-called black hat SEO operative. Conversations are neither [...]

Comment Post by: Should a targeted country strike back at the cyber attackers? by Dancho Danchev « surflightroy — February 5th, 2011 @ 3:21 am EST  Reply

[...] into the malicious mix, with notable examples including the abuse of legitimate services such as, Twitter, Google Groups, Facebook as command and control servers, as well as Amazon’s EC2 as a [...]

Comment Post by: Snoep76239 — March 11th, 2011 @ 2:14 am EST  Reply

Why “steal” personal information when every FarcebookTweeter give it all away voluntarily?
Social networking is a stalker’s or social engineer’s wet dream.
So many peoples’ passwords are their dog’s name, backwards birthday, or can be gotten by using a dictionary based on their interests. Brute force, schmute force.

Comment Post by: Hackers Use Twitter to Control Botnet « www.unixbox.org — April 22nd, 2011 @ 12:13 am EST  Reply

[...] Network’s Jose Nazario, an expert on botnets, discovered the so-called command-and-control structure. Infected computers were following the Twitter feed [...]

Comment Post by: Dipl.-Inform. Carsten Eilers — June 16th, 2011 @ 4:08 am EST  Reply

Botnets – Zombie-Plagen im Internet…

Die mit einer spezifischen Schadsoftware infizierten Rechner werden oft zu sog. Botnets zusammengefasst. Wie die Schadsoftware verbreitet wurde, egal ob als Virus, Wurm, Trojaner, Drive-by-Infektion oder wie auch immer, ist dabei egal. Die infiz…

Comment Post by: An Innovative Control and Lame – Twitter Being Used As Botnet Command Channel « wnnsnn — July 19th, 2011 @ 4:59 pm EST  Reply

[...] Twitter-based Botnet Command Channel [...]

Comment Post by: Amazon's Cloud Services Systematically Exploited by Cybercriminals | Vishnu Valentino Hacking Tutorial, Tips and Trick — July 31st, 2011 @ 2:14 am EST  Reply

[...] crimeware in the cloud have a future? Most certainly, as cybercriminals appear to have been actively [...]

Leave a Comment