twitter ios iconWe've been following for some time the story of the Flashback trojan that has been targeting Mac users by masquerading as a Flash Player installer but which has also been evolving to include increasingly sophisticated tactics for infecting users' computers.

Antivirus firm Intego now reports that Flashback's creators are using an interesting new tactic for communicating with machines infected by the trojan: Twitter. According to the report, Flashback is programmed to search Twitter for Tweets containing a unique 12-digit code that changes daily, with the malware's authors being able to issue commands to infected computers by posting from any number of Twitter accounts simply by including the appropriate code as a hashtag.

These hashtags aren’t as simple as, say, #Flashback or #MacMalwareMaster, but are seemingly random strings of characters that change each day. Intego’s malware research team cracked the 128-bit RC4 encryption used for Flashback’s code and discovered the keys to this system.

The hashtags are made up of twelve characters. There are four characters for the day, four characters for the month, and four characters for the year. [...]

So, for today, March 5, 2012, the hashtag would be #pepbyfadxeoa.

Intego is monitoring Twitter to look for any commands being issued using the hashtag codes, also noting that Flashback uses a number of different user agent strings in its web queries looking for the Twitter contacts, seeking to avoid detection and removal.

Top Rated Comments

GGJstudios Avatar
126 months ago
I just upgraded my gfs flashplayer last week ... What are the chances that it's this Trojan ?? How can I check?
Go to your /Users/yourusername/Library/ folder and look to see if you find any of these files:
~/.MacOSX/environment.plist
~/Library/LaunchAgents/com.apple.SystemUI.plist
~/Library/Preferences/perflib
~/Library/Preferences/Preferences.dylib
~/Library/Logs/swlog
If you don't have any of these files, you're not infected.

Your Library folders are hidden by default in Lion. To get to your /Library or /Users/yourusername/Library (also known as the ~/Library) folders in Lion, Launch Finder and click Go > Go to Folder and type: /Library or ~/Library

Here's how to avoid any question:
With my flash player I'm careful. I never click on a pop-up when it tells me it's out of date.

I go to Adobe's site and update there.
This is very important:
To repeat: the vendor has provided no actual evidence that such messages are happening.
In fact, while I may have missed it, I've seen no corroborating evidence supporting the recent reports coming from Intego. I haven't seen any other security firm confirming the presence of these variations, or the variation that supposedly installs itself without user intervention, as they also claim. Until such claims are proven by other companies, I'll continue to find Intego's claims suspicious, at best.

Generally speaking, these reports by security firms are little more than thinly veiled attempts to scare users into buying their security software, which you don't need. However, such reports can be useful reminders for users to continue to practice safe computing.
[LIST=1]
* Make sure your built-in Mac firewall is enabled in System Preferences > Security > Firewall


* Uncheck "Open "safe" files after downloading" in Safari > Preferences > General


* Uncheck "Enable Java" in Safari > Preferences > Security. Leave this unchecked until you visit a trusted site that requires Java, then re-enable only for your visit to that site. (This is not to be confused with JavaScript, which you should leave enabled.)


* Check your DNS settings by reading this (https://guides.macrumors.com/Mac_Virus/Malware_FAQ#Why_am_I_being_redirected_to_other_sites.3F).


* Be careful to only install software from trusted, reputable sites. Never install pirated software. If you're not sure about an app, ask in this forum before installing.


* Never let someone else have physical access to install anything on your Mac.


* Always keep your Mac and application software updated. Use Software Update for your Mac software. For other software, it's safer to get updates from the developer's site or from the menu item "Check for updates", rather than installing from any notification window that pops up while you're surfing the web.

That's all you need to do to keep your Mac completely free of any virus, trojan, spyware, keylogger, or other malware.

You don't need any 3rd party antivirus app to keep your Mac malware-free. Macs are not immune to malware, but no true viruses exist in the wild that can run on Mac OS X, and there never have been any since it was released over 10 years ago. You cannot infect your Mac simply by visiting a website, unzipping a file, opening an email attachment or joining a network. The only malware in the wild that can affect Mac OS X is a handful of trojans, which cannot infect your Mac unless you actively install them, and they can be easily avoided with some basic education, common sense and care in what software you install. Also, Mac OS X Snow Leopard and Lion have anti-malware protection (http://support.apple.com/kb/ht4651) built in, further reducing the need for 3rd party antivirus apps.
Mac Virus/Malware FAQ (https://guides.macrumors.com/Mac_Virus/Malware_FAQ)
Score: 8 Votes (Like | Disagree)
FloatingBones Avatar
126 months ago
The claim is interesting, but a quick search on Twitter doesn't show that #pepbyfadxeoa is actually being used by any program for anything. If the vendor's claim is true, they should be able to tell us a prior hashtag which shows actual nefarious activity.

We are still suffering from Adobe's lax attitudes for security around their products. All of the "Get Flash Player" and "Get Adobe PDF Reader" links that Adobe encouraged in the past have helped foster a lackadaisical attitude towards the clear risk of installing a trojan horse on machines. I will be happy as Flash on the WWW continues to fade into the sunset.

I think this uses twitter even if you don't use it personally, they are just using the open nature of the site as a means to communicate with the malware.
Bingo. If the trojan is actually using twitter as a conduit, it's probably using accounts that were embedded in the trojan. Blocking those would require the blocking of connections to twitter servers with something like Little Snitch (http://www.obdev.at/products/littlesnitch/index.html)
or outbound blocks in your network's firewall.

To repeat: the vendor has provided no actual evidence that such messages are happening. I see no evidence with todays hashtag.

One other note: the Twitter stream is a real cesspool these days. As far as I can tell, Twitter does nothing to automatically remove the 'bot accounts that send out Amazon Associates link-spam. They're also doing nothing to automatically censor accounts that send @mentions that spam the "adult" dating sites. Doesn't Twitter have any friends in the Valley who could help them keep the toxic pollution out of their stream?
Score: 7 Votes (Like | Disagree)
GGJstudios Avatar
126 months ago

Much like life, if you hang around in bars, you can come down with diseases.
So if you don't hang around in bars, you won't catch any diseases???
Score: 6 Votes (Like | Disagree)
FloatingBones Avatar
126 months ago
I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.

I'm even more suspicious when the claimed evidence doesn't pan out. To alter the slogan from that famous Wendy's commercial (//www.youtube.com/watch?v=Ug75diEyiA0):

Where's the tweets? :D
Score: 5 Votes (Like | Disagree)
mijail Avatar
126 months ago
I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.

Word, bro. And what about those pesky "doctors" who seem to know all about illnesses and bacteria and whatnot? Damned scientists!
(Fricking magnets, how do they work?)

----------

Then you can send a message to the hacker how dumb he was. With the same amount of work he had put into this malware he could have created an app and probably made some money.

You mean he has no bussiness plan for this?
Score: 4 Votes (Like | Disagree)
Amazing Iceman Avatar
126 months ago
Nasty!!

(I'm breaking my arm patting myself on the back for my non-involement with social media.)

I do feel bad for the majority of the world who does use social media...this is really lousy.

Much crap on social media, but a tremendous amount of good in places where free expression is only possible through Twitter, etc. It's a powerful tool for many in the world, and any sympathy I might have for certain hackers is totally absent in situations like this.

Well, don't over pad yourself. The infection doesn't come from Twitter, but from a fake Adobe Flash Installer. Twitter is only one of the many ways hackers use to communicate with the hacked Macs.
Score: 3 Votes (Like | Disagree)

Related Stories

youtube apple tv

YouTube Discontinuing 3rd-Generation Apple TV App, AirPlay Still Available

Wednesday February 3, 2021 3:09 pm PST by
YouTube is planning to stop supporting its YouTube app on the third-generation Apple TV models, where YouTube has long been available as a channel option. A 9to5Mac reader received a message about the upcoming app discontinuation, which is set to take place in March.Starting early March, the YouTube app will no longer be available on Apple TV (3rd generation). You can still watch YouTube on...
iPhone 13 Dummy Thumbnail 2

Kuo: iPhone 13 to Feature LEO Satellite Communications to Make Calls and Texts Without Cellular Coverage

Sunday August 29, 2021 7:39 am PDT by
The iPhone 13 will feature low earth orbit (LEO) satellite communication connectivity to allow users to make calls and send messages in areas without 4G or 5G coverage, according to the reliable analyst Ming-Chi Kuo. In a note to investors, seen by MacRumors, Kuo explained that the iPhone 13 lineup will feature hardware that is able to connect to LEO satellites. If enabled with the relevant...
General Apps Messages

Android iMessage Competitor Puts Pressure on Apple

Friday July 30, 2021 3:15 am PDT by
Google and the three major U.S. carriers, including Verizon, AT&T, and T-Mobile, will all support a new communications protocol on Android smartphones starting in 2022, a move that puts pressure on Apple to adopt a new cross-platform messaging standard and may present a challenge to iMessage. Verizon recently announced that it is planning to adopt Messages by Google as its default messaging...
os x mountain lion macs 16x9 2

Apple Makes OS X Lion and Mountain Lion Free to Download

Wednesday June 30, 2021 12:19 pm PDT by
Apple recently dropped the $19.99 fee for OS X Lion and Mountain Lion, making the older Mac updates free to download, reports Macworld. Apple has kept OS X 10.7 Lion and OS X 10.8 Mountain Lion available for customers who have machines limited to the older software, but until recently, Apple was charging $19.99 to get download codes for the updates. As of last week, these updates no...
bluetti eb70 main

MacRumors Giveaway: Win a Bluetti EB70 Portable Power Station and 200W Solar Panel

Friday September 3, 2021 11:13 am PDT by
For this week's giveaway, we've teamed up with MAXOAK to offer MacRumors readers a chance to win a Bluetti portable power station and an accompanying solar panel. Bluetti makes a range of portable power station options that are useful for camping, emergencies, power outages, off-grid living, and similar situations. The Bluetti EB70 is a solid middle of the road option that offers 716Wh and...
apple privacy

Apple Publishes FAQ to Address Concerns About CSAM Detection and Messages Scanning

Monday August 9, 2021 1:50 am PDT by
Apple has published a FAQ titled "Expanded Protections for Children" which aims to allay users' privacy concerns about the new CSAM detection in iCloud Photos and communication safety for Messages features that the company announced last week. "Since we announced these features, many stakeholders including privacy organizations and child safety organizations have expressed their support of...
General Spotify Feature

Spotify Pauses Plans to Add AirPlay 2 Support to iOS App [Update: Spotify Clarifies]

Friday August 6, 2021 9:07 am PDT by
See update at bottom of article Spotify this week confirmed that its plans to add AirPlay 2 support to its iOS app have been placed on indefinite hiatus. In an online discussion forum post, a Spotify representative said the streaming music service had been working on supporting AirPlay 2, but the company has paused the efforts "for now" due to "audio driver compatibility issues." The...
iphone 13 teal with text

Apple Begins Preparation for iPhone 13 Production Ahead of Fall Launch

Monday June 28, 2021 3:29 am PDT by
We're just a few months away from when Apple is expected to reveal the 2021 iPhone, dubbed the "iPhone 13." In preparation for its launch, it has been pulling in shipments of different components needed to produce the new iPhones, according to a report from DigiTimes. In years past, Apple released its latest iPhone lineup, alongside a new Apple Watch, during a September event at Apple Park....
General Spotify Feature

Spotify Partners With Delta to Provide Free In-Flight Music and Podcasts Service

Thursday September 2, 2021 12:59 am PDT by
Spotify has announced a new partnership with Delta that will see the streaming service take over the "audio" section of Delta's in-flight seatback entertainment, making select playlists and podcasts freely available to all passengers. You are now free to roam about the cabin—and get the music and podcasts you love at 30,000 feet. Beginning today, we're taking off in a new partnership with...
iphone 12 colors 2021

iPhone 12 Colors: Deciding on The Right Color

Thursday November 5, 2020 8:35 am PST by
The iPhone 12 and iPhone 12 Pro arrived in October 2020 in a range of color options, with entirely new hues available on both devices, as well as some popular classics. The 12 and 12 Pro have different color choices, so if you have your heart set on a particular shade, you might not be able to get your preferred model in that color. iPhone 12 mini and iPhone 12 The iPhone 12 mini and iPhone...