Flashback Malware Authors Using Twitter to Talk to Infected Machines

by

We've been following for some time the story of the Flashback trojan that has been targeting Mac users by masquerading as a Flash Player installer but which has also been evolving to include increasingly sophisticated tactics for infecting users' computers.

Antivirus firm Intego now reports that Flashback's creators are using an interesting new tactic for communicating with machines infected by the trojan: Twitter. According to the report, Flashback is programmed to search Twitter for Tweets containing a unique 12-digit code that changes daily, with the malware's authors being able to issue commands to infected computers by posting from any number of Twitter accounts simply by including the appropriate code as a hashtag.

These hashtags aren’t as simple as, say, #Flashback or #MacMalwareMaster, but are seemingly random strings of characters that change each day. Intego’s malware research team cracked the 128-bit RC4 encryption used for Flashback’s code and discovered the keys to this system.

The hashtags are made up of twelve characters. There are four characters for the day, four characters for the month, and four characters for the year. [...]

So, for today, March 5, 2012, the hashtag would be #pepbyfadxeoa.

Intego is monitoring Twitter to look for any commands being issued using the hashtag codes, also noting that Flashback uses a number of different user agent strings in its web queries looking for the Twitter contacts, seeking to avoid detection and removal.

Top Rated Comments

(View all)
Avatar
113 months ago

I just upgraded my gfs flashplayer last week ... What are the chances that it's this Trojan ?? How can I check?

Go to your /Users/yourusername/Library/ folder and look to see if you find any of these files:
~/.MacOSX/environment.plist
~/Library/LaunchAgents/com.apple.SystemUI.plist
~/Library/Preferences/perflib
~/Library/Preferences/Preferences.dylib
~/Library/Logs/swlog
If you don't have any of these files, you're not infected.

Your Library folders are hidden by default in Lion. To get to your /Library or /Users/yourusername/Library (also known as the ~/Library) folders in Lion, Launch Finder and click Go > Go to Folder and type: /Library or ~/Library

Here's how to avoid any question:

With my flash player I'm careful. I never click on a pop-up when it tells me it's out of date.

I go to Adobe's site and update there.

This is very important:

To repeat: the vendor has provided no actual evidence that such messages are happening.

In fact, while I may have missed it, I've seen no corroborating evidence supporting the recent reports coming from Intego. I haven't seen any other security firm confirming the presence of these variations, or the variation that supposedly installs itself without user intervention, as they also claim. Until such claims are proven by other companies, I'll continue to find Intego's claims suspicious, at best.

Generally speaking, these reports by security firms are little more than thinly veiled attempts to scare users into buying their security software, which you don't need. However, such reports can be useful reminders for users to continue to practice safe computing.
[LIST=1]
* Make sure your built-in Mac firewall is enabled in System Preferences > Security > Firewall


* Uncheck "Open "safe" files after downloading" in Safari > Preferences > General


* Uncheck "Enable Java" in Safari > Preferences > Security. Leave this unchecked until you visit a trusted site that requires Java, then re-enable only for your visit to that site. (This is not to be confused with JavaScript, which you should leave enabled.)


* Check your DNS settings by reading this (https://guides.macrumors.com/Mac_Virus/Malware_FAQ#Why_am_I_being_redirected_to_other_sites.3F).


* Be careful to only install software from trusted, reputable sites. Never install pirated software. If you're not sure about an app, ask in this forum before installing.


* Never let someone else have physical access to install anything on your Mac.


* Always keep your Mac and application software updated. Use Software Update for your Mac software. For other software, it's safer to get updates from the developer's site or from the menu item "Check for updates", rather than installing from any notification window that pops up while you're surfing the web.

That's all you need to do to keep your Mac completely free of any virus, trojan, spyware, keylogger, or other malware.

You don't need any 3rd party antivirus app to keep your Mac malware-free. Macs are not immune to malware, but no true viruses exist in the wild that can run on Mac OS X, and there never have been any since it was released over 10 years ago. You cannot infect your Mac simply by visiting a website, unzipping a file, opening an email attachment or joining a network. The only malware in the wild that can affect Mac OS X is a handful of trojans, which cannot infect your Mac unless you actively install them, and they can be easily avoided with some basic education, common sense and care in what software you install. Also, Mac OS X Snow Leopard and Lion have anti-malware protection (http://support.apple.com/kb/ht4651) built in, further reducing the need for 3rd party antivirus apps.
Mac Virus/Malware FAQ (https://guides.macrumors.com/Mac_Virus/Malware_FAQ)
Score: 8 Votes (Like | Disagree)
Avatar
113 months ago
The claim is interesting, but a quick search on Twitter doesn't show that #pepbyfadxeoa is actually being used by any program for anything. If the vendor's claim is true, they should be able to tell us a prior hashtag which shows actual nefarious activity.

We are still suffering from Adobe's lax attitudes for security around their products. All of the "Get Flash Player" and "Get Adobe PDF Reader" links that Adobe encouraged in the past have helped foster a lackadaisical attitude towards the clear risk of installing a trojan horse on machines. I will be happy as Flash on the WWW continues to fade into the sunset.

I think this uses twitter even if you don't use it personally, they are just using the open nature of the site as a means to communicate with the malware.

Bingo. If the trojan is actually using twitter as a conduit, it's probably using accounts that were embedded in the trojan. Blocking those would require the blocking of connections to twitter servers with something like Little Snitch (http://www.obdev.at/products/littlesnitch/index.html)
or outbound blocks in your network's firewall.

To repeat: the vendor has provided no actual evidence that such messages are happening. I see no evidence with todays hashtag.

One other note: the Twitter stream is a real cesspool these days. As far as I can tell, Twitter does nothing to automatically remove the 'bot accounts that send out Amazon Associates link-spam. They're also doing nothing to automatically censor accounts that send @mentions that spam the "adult" dating sites. Doesn't Twitter have any friends in the Valley who could help them keep the toxic pollution out of their stream?
Score: 7 Votes (Like | Disagree)
Avatar
113 months ago


Much like life, if you hang around in bars, you can come down with diseases.

So if you don't hang around in bars, you won't catch any diseases???
Score: 6 Votes (Like | Disagree)
Avatar
113 months ago

I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.


I'm even more suspicious when the claimed evidence doesn't pan out. To alter the slogan from that famous Wendy's commercial (//www.youtube.com/watch?v=Ug75diEyiA0):

Where's the tweets? :D
Score: 5 Votes (Like | Disagree)
Avatar
113 months ago

I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.


Word, bro. And what about those pesky "doctors" who seem to know all about illnesses and bacteria and whatnot? Damned scientists!
(Fricking magnets, how do they work?)

----------

Then you can send a message to the hacker how dumb he was. With the same amount of work he had put into this malware he could have created an app and probably made some money.


You mean he has no bussiness plan for this?
Score: 4 Votes (Like | Disagree)
Avatar
113 months ago

Nasty!!

(I'm breaking my arm patting myself on the back for my non-involement with social media.)

I do feel bad for the majority of the world who does use social media...this is really lousy.

Much crap on social media, but a tremendous amount of good in places where free expression is only possible through Twitter, etc. It's a powerful tool for many in the world, and any sympathy I might have for certain hackers is totally absent in situations like this.


Well, don't over pad yourself. The infection doesn't come from Twitter, but from a fake Adobe Flash Installer. Twitter is only one of the many ways hackers use to communicate with the hacked Macs.
Score: 3 Votes (Like | Disagree)

Top Stories

Early iPhone 12 Tests Show Ceramic Shield is Stronger and More Scratch Resistant Than iPhone 11 Glass

Friday October 23, 2020 1:21 pm PDT by
Apple's new iPhone 12 models are protected by a Ceramic Shield cover glass that has nano-ceramic crystals infused right into the glass to improve durability. According to Apple, Ceramic Shield offers four times better drop protection than the glass used for the iPhone 11 models. YouTube channel MobileReviewsEh conducted some tests on the iPhone 12 using a force meter to compare its performance ...

First Impressions From New iPhone 12 and 12 Pro Owners

Thursday October 22, 2020 4:20 pm PDT by
It's already Friday, October 23, in Australia and New Zealand, which means some customers who purchased an iPhone 12 or 12 Pro already have their new devices in hand. We've seen dozens of reviews of the iPhone 12 and iPhone 12 Pro from media sites, but now first impressions from regular Apple customers are available. Image via MacRumors reader Boardiesboi New iPhone 12 and 12 Pro owners are...

iPhone 12 Pro Allows You to Measure Someone's Height Instantly Using LiDAR Scanner

Saturday October 24, 2020 11:12 am PDT by
iPhone 12 Pro models feature a new LiDAR Scanner for enhanced augmented reality experiences, but the sensor also enables another unique feature: the ability to measure a person's height instantly using the Measure app. You can even measure the seated height of a person in a chair, according to Apple. When the Measure app detects a person in the viewfinder, it automatically measures their...

Apple VP Kaiann Drance Interview Addresses Battery Life, MagSafe, and Power Adapter Concerns

Friday October 23, 2020 3:37 am PDT by
Apple's Vice President of iPhone Marketing, Kaiann Drance, has provided a new interview to Rich DeMuro on the Rich on Tech Podcast, to discuss the iPhone 12 and iPhone 12 Pro. Although much of the interview repeated points from Apple's "Hi, Speed" event, there were a number of interesting tidbits regarding the affect of 5G on battery life, MagSafe concerns, and the lack of a power adapter in...

iPhone 11 Pro Outlasts iPhone 12 and 12 Pro in Extensive Battery Life Test

Friday October 23, 2020 8:36 am PDT by
Arun Maini today shared a new side-by-side iPhone battery life video test on his YouTube channel Mrwhosetheboss, timing how long the new iPhone 12 and iPhone 12 Pro models last on a single charge compared to older models, with equal brightness, settings, battery health, and usage. All of the devices are running iOS 14 without a SIM card inserted. In the test, the iPhone 11 Pro outlasted both ...

Apple Distributing New Heated Display Removal Machine for iPhone 12 Repairs

Thursday October 22, 2020 6:20 pm PDT by
Apple is providing Genius Bars and Apple Authorized Service Providers with a new heated display removal fixture for iPhone 12 and iPhone 12 Pro repairs, according to information obtained by MacRumors from a reliable source. To open iPhone 12 models, technicians will be required to slide the device into a specialized tray, and then place the tray into the high-temperature fixture for two...

Apple Warns MagSafe Charger Can Leave Circular Imprints on Leather Cases

Friday October 23, 2020 3:23 pm PDT by
If you keep your iPhone in a leather case while charging with Apple's new MagSafe Charger, the case might show circular imprints from contact with the accessory, according to a new Apple support document published today. Apple's leather cases for the iPhone 12 and iPhone 12 Pro are not available until November 6, but a MacRumors reader has already shared a photo of a circular imprint on...

MagSafe Charger Teardown Reveals Simple Design With Magnets and Charging Coil Encircling a Small Circuit Board

Friday October 23, 2020 7:50 am PDT by
iFixit has today shared a teardown of Apple's new MagSafe charger for the iPhone 12 and iPhone 12 Pro. An X-ray of the MagSafe charger courtesy of Creative Electron reveals the internal charging coil surrounded by a circular arrangement of magnets within the puck. The only seam that iFixit was able to leverage to open the device was where the white rubber circle meets the metal rim,...

PSA: Non-iPhone 12 Models Charge Super Slowly With MagSafe Charger

Friday October 23, 2020 4:11 pm PDT by
Alongside the iPhone 12 models, Apple introduced a new $39 MagSafe Charger that's meant to work with the magnets in the iPhone 12 Pro models to charge them up at a maximum of 15W. The MagSafe Charger is technically able to be used with older iPhones, but it's not a good idea because the charging with non-iPhone 12 devices is so slow. We did two tests with the iPhone XS Max, draining the...

New Photos Offer Better Look at iPhone 12 Color Options

Tuesday October 20, 2020 2:34 am PDT by
As we wait for the iPhone 12 review embargo to lift later today, more pictures are circulating of the devices in real-world lighting conditions, providing a better look at the different colors available. Leaker DuanRui has shared images on Twitter of the iPhone 12 in white, black, blue, green, and (PRODUCT)RED. The black and white colors are similar to the iPhone 11 colors, but the other...