Home > Online Media Daily > Thursday, Oct 15, 2009

Botnet Attack Spreads Virus Through Twittersphere

by Laurie Sullivan, Oct 14, 2009, 6:24 PM
  • Comment
  • Recommend (10)

Subscribe to Online Media Daily


TAGS
cyber security, twitter


Twitterbird/robot

The Twittersphere came under a phishing attack Wednesday that sent direct messages to Twitterers. The messages, which appear to be sent by a follower, contained a link that asked the person to type in personal information and password.

Some of the messages ask Twitter users to click on a link to view a video. Others ask for personal information, including passwords. Amy Marshall (@amystweeting) based in Sigonella, Sicily, Italy wrote: "Twitter virus? I got an email saying I signed up for a twitter app subscription which I DID NOT! So I didn't click the link."

@andtwinsmake5 was sent more than seven phishing direct message links from followers. @benlucier wrote: "ifortune4u.com virus/phishing/spyware mess on Twitter right now. Lots of DMs from peeps. Be careful out there, wear your Twitter condom!"

ClickForensics (@ClickForensics) sent an apology to its followers after the virus gained access to its password and took over the company's Twitter account. "Twitter DM was attacked today. To all who received DMs from us ... apologies ... we did not DM our followers. We got lots of spam, too," the post read.

Steve O'Brien, ClickForensics' vice president of marketing, doesn't quite have a handle on the scope of the attack, but surmises it involves "hundreds of thousands of accounts" based on the chatter on Twitter and his experience.

At 11:12 a.m. PST O'Brian received a direct message from another corporate account he follows on Twitter. The message read: "I think I see you here in this video." It also provided a link. O'Brian clicked on the link, which took him to a page that resembled a Twitter log in page that asked for an account name and a password. When he entered the information, a fail whale page came up that read: Twitter is overloaded. Come back later.

Both Anchor Intelligence Product Marketing Manager Carrie Bourguignon, and Vice President of Product Management and Marketing Richard Sim say the virus was part of an organized effort to lift data. "Say Joe's computer has been infected with spyware," Bourguignon says. That spyware has logged the keystrokes for Joe's account credentials and uses them to access his various accounts, including his Twitter account. It is then easy for the fraudster to write a script to go through Joe's list of followers on Twitter and insert text into a direct message for all of those followers."

That text likely has a link to a malicious site that will deliver executable code to Joe's followers' computers through a virus. It occurs through a trusted relationship, so the infection rate rises for email spam or ads. The use of shortened URLs, such as those created through bit.ly and TinyURL, also contributes to the process because the shortened URLs easily mask the follower's destination, Bourguignon explains.

Joe's machine need not have been infected for this downward spiral to occur. A Twitter breach, if a fraudster hacked into Twitter, is another way for the person to have gained access to Joe's account.

"We saw similar activity when I was at Hotmail," Sim says. "Hacked accounts are a goldmine for perpetrators looking to distribute their infections. The 'trusted relationships' involved in email, Twitter, Facebook and others make the infection rates through these channels much higher than through spam from anonymous addresses."

Ironically, Twitter's API Guru Marcel Molina tweeted about adding a "Report as spam" button to twitter.com to now "also simultaneously block and report a user as a spammer via the API."

"Realize that no automated action is taken from the report being created, but know your request has been received," he writes.

twitter virus



  • Comment
  • Recommend (10)

Be the first to comment on "Botnet Attack Spreads Virus Through Twittersphere".

Leave a Comment

You must be a member to comment. Become a Member




MOST READ

FOLLOW MEDIAPOST
  • Join
    Join over 100,000 media, advertising and marketing professionals for Free MediaPost Membership. Member Benefits »
  • Follow MediaPost News on LinkedIn Today

ARCHIVES
Recent Online Media Daily Articles
Twitter Offers SMBs Self-Serve Ads With Help From American Express  
Twitter will roll out its self-service ad platform to small and mid-size businesses in March through ...
FTC: Apps For Kids Fall Short On Privacy  
  Developers of childrens' apps often fail to adequately tell parents what data the apps collect, ...
Mobile Site Investments, Search Growing  
Nearly half of the travel industry's annual paid-search campaign impressions occur between May and August. With ...
Opera Acquires Mobile Theory, 4th Screen   
Pushing further into mobile advertising, Opera Software is acquiring a pair of mobile ad networks: U.S.-based Mobile ...
Samsung's Social Media Campaign Personalizes Olympics  
Samsung, a global Olympic sponsor for the 2012 Summer Olympics in London, is launching a multiplatform ...
SMG Serves Video With Daily Meal  
In January 2011, Spanfeller Media Group proudly launched a pretty, new food site, The Daily Meal. ...
Users Accept More Video Ads  
During the fourth quarter of 2011, video ad volume growth outpaced video viewing volume growth for the ...
Velti To Debut Private Exchange For Premium Publishers  
Of interest to mobile marketers, Velti on Thursday plans to debut a new private exchange for ...
GroupM: Search Good For What Ails Pharma Brands  
Pharmaceutical companies spent billions in advertising last year, but search only accounted for 2.6%. New research ...
Apple Promises To Crack Down On Privacy Violations  
Faced with reports that app developers are scooping up iPhone users' address books without their permission, ...
>> Online Media Daily Archives 
ABOUT MEDIAPOST • CONTACT EDITORIAL • MEDIA KIT • RSS FEEDS • PRIVACY/TERMS & CONDITIONS
©2012 MediaPost Communications. All rights reserved.
15 East 32nd Street, 7th Floor, New York, NY 10016
feedback@mediapost.com