The Register® — Biting the hand that feeds IT

Feeds

Twitter Trends exploited to promote scareware

Malign micro-blogging madness

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Hackers are manipulating a hot topics feature of Twitter to promote malware-infected websites. The gaming of the Twitter Trends feature recalls the manipulation of Google search results using black-hat search engine optimisation techniques.

In the case of the Twitter attack, cyber-criminals created hundreds of accounts and posted multiple messages under the topic "PhishTube Broadcast", a reference to the US rock band Phish, but containing links to a spoof pornographic Web page. The topic appeared in the Trending Topic list, achieving greater visibility and therefore more user traffic to comments made under that category.

Users intrigued enough to visit the supposed websites promoted through the Twitter social-engineering ruse risk exposure to the PrivacyCenter fake antivirus (scareware) package. The software runs a spoof scan of system before falsely informing users that their computers are infected with malware, whether they are or not, in order to induce frightened users into buying software of little or not utility.

Attacks of this nature promoting a scareware package called System Security surfaced last week. The latest run of attacks demonstrates a continuation of the same methods, and its adaptation to make the ruse seem more plausible and likely to attract notice.

"We have recently been warning of an increase in BlackHat SEO attacks (malicious techniques to improve search engine rankings), particularly those aimed at selling fake antivirus products," said Luis Corrons, Technical Director of PandaLabs. "In this case, instead of a search engine, the Twitter ranking mechanism is the target of the attack, forcing topics to appear in the list of the most popular. Anyone interested in this topic will most likely end up on one of the thousands of malicious comments posted, although we have also seen a few legitimate comments".

A write-up of the attacks - complete with screen-shots - by Panda Security can be found here.

The targeting of Twitter is similar to recent attacks on other Web 2.0 websites, such as Digg.com and YouTube. ®

Agentless Backup is Not a Myth

Latest Comments
Anonymous Coward

Twitter - a phenomonal WANK

Phenomonal wanks are for wankers.....

0
0

Well, they came to the right place

There will be plenty of twits (twats?) who'll regularly fall for this crap.

@Fail

0
0

Checked out the link on the YouTube problem...

...and it pretty much sums up why, whenever I upload a fresh video to any of my YouTube channels, the first thing I do is disable comments of any kind, either written or video responses. Come to think of it, I'm surprised that I haven't seen any video response spam, nor heard any news about malicious links in those annoying-assed pop-up ads that occasionally infest YouTube (I go there with JavaScript disabled, so I see them very rarely).

When I first started posting there, I left comments open, but after about the third go-round of having to scrape out the flamage and the sex/dating site spam, I decided the hell with it, and went back and reset the preferences on stuff I'd already uploaded to "do not allow comments", and began disabling comments on my new uploads from then on. Presto, zero headaches.

As far as grammatical matches for nailing Twitter spam...I don't know about anyone else here, but long ago I set up a filter rule flagging my email spam based on identical instances of spelling/grammatical mangling -- almost as if it were written by a Chinese, or badly translated from Chinese -- that appeared repeatedly in multiple spams, usually for C1AL!5 or V1AGRA or some bogus herbal crap; for instance, I was able to nail a fair amount of Chinese bogus medicine spams by using the keyword "sidebacks" -- where the writer obviously meant to say "side effects".

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Internet fraud still stings suckers
Australians twice as gullible as Americans