NEWS - April 30, 2012
by Carol~
- 4/30/12 8:21 AM
Flashback bots search Twitter for controllers, hit Snow Leopard hardest
Malware investigators for the Russian antivirus company Dr. Web report that the latest version of Flashback, the backdoor malware targeting Macs through a Java exploit, is using Twitter as a backup command and control network.
Dr. Web was the first to report on the rapidly growing Flashback botnet—the largest recorded malware attack ever focused on Macs. In an analysis of current variants of the malware, Dr. Web's team found that the Trojan software installed through the Java exploit is initially configured with a list of servers through which it can receive additional commands and configuration updates. If the malware doesn't get a correct response from one of the control servers in its own internal generated list, it will search Twitter for posts containing a string of text generated from the current date, and look for a control server address embedded in the posts.
"For example, some Trojan versions generate a string of the 'rgdgkpshxeoa' format for the date 04.13.2012," the Dr. Web team wrote in their blog post. "If the Trojan manages to find aTwitter message containing bumpbegin and endbump tags enclosing a control server address, it will be used as a domain name."
The Dr. Web team started using Twitter posts in an effort to "sinkhole" the botnet on April 13. But by the next day, the Twitter account they were using was blocked.
Continued : http://arstechnica.com/apple/news/2012/04/flashback-bots-search-twitter-for-controllers-hit-snow-leopard-hardest.ars
Also:
Snow Leopard users most prone to Flashback infection
Flashback Trojan Most Present on Snow Leopard Machines

Moderator
CNET Staff
Samsung Staff
Dell Staff