ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Cybercriminals hijack Twitter trending topics to serve malware

By | June 9, 2009, 10:47am PDT

Summary: A currently ongoing malware serving campaign across Twitter, is continuing to abuse the momentum offered by Twitter’s trending topics in order to trick users into visiting bogus exclusive video sites and infect them with malware. The campaign, spreading since last week, is relying on a growing number of automatically registered bogus Twitter accounts, which combine trending [...]

A currently ongoing malware serving campaign across Twitter, is continuing to abuse the momentum offered by Twitter’s trending topics in order to trick users into visiting bogus exclusive video sites and infect them with malware.

The campaign, spreading since last week, is relying on a growing number of automatically registered bogus Twitter accounts, which combine trending topics and hashtags with custom messages and pre-defined Tinyurl links, all leading to identical fake codec which is droping three different malware samples.

Let’s dissect their activities, and find a common pattern of exploitation.

This very latest campaign once again demonstrates that malicious parties do not maintain a static list of potentially dangerous keywords, in fact, thanks to the dynamic nature of today’s Web, they serve malware in real-time by automatically syndicating the Web’s buzz and mixing it with malicious content hosted on legitimate services whose high pageranks ensure the lowest possible time frame for having their content crawled by public search engines.

What has changed since last week is the intensity of the campaign, which now includes many new topics, which the bogus accounts advertise with over 150 tweets on average during a period of 24 hours.

The tweets are generated by using popular hashtag or Trending topics combined with their campaign message and a relatively static Tinyurl link.

Here are some of the topics currently used in the campaign:

  • Shocking video today, Headline news video, Shocking news theme
  • Airplance crashes theme, for instance, Jumbo Jet 747 on fire, 280 deaths, Little Cessna crash in Vancouver, Airbus A330-200 Crash Video, Young childred killed in car crash, Terrible car crash in Fresno, CA, 15 deaths, online video, Airbus A330-200 Crash Video, AA AIRBUS A340 CRASH in Auburn, 189 fatalities
  • Celebrities in front of shopping mall theme
  • Rape theme - Raped Tonight by 20 skinheads - HEADLINE News Video, Pedophile raped over 580 children, Rihanna Raped Tonight by 20 skinheads in Maryland State. VIDEO

Upon following any of the links, the users are redirected to a Mal/FakeAV-AY (streamviewer.40030.exe) serving site attempting to trick the visitors with a common social engineering theme, the lack of required codec in order to view the video.

Cybercriminals adapt pretty fast, for instance, last week’s campaign was using the bit.ly URL-shortening service which does cross-check submitted URLs for possible maliciousness using community-driven databases.

The effectiveness of this common sense technique is best described with the “Warning - this site has been flagged by SURBL and may contain unsolicited content.” message served for the very same domain that the malicious parties are now freely redirecting to through TinyURL.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
2
Comments

Join the conversation!

Just In

RE: Cybercriminals hijack Twitter trending topics to serve malware
birumut Updated - 2nd May 2011
Well done! Thank you very much for professional templates and community edition
seslisohbet seslichat
0 Votes
+ -
inadequate response by Sers Holding Company
jasonwright365@... 10th Jun 2009
I would have preferred that they say, "We goofed up. Sorry. We've fired the person who made this decision" instead of "Sorry that we didn't tell you we were going to record every single move on your computer including any credit card number or (heaven forbid) social security # you might happen to type or any personal correspondence"

Note to anyone, don't buy computers from sears. Did they really think this would improve their business model?
Well done! Thank you very much for professional templates and community edition
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix