A recently discovered piece of malware has a unique way of communicating with its creator—through an internet meme posted on Twitter.
The mysterious hacker has been using the "What if I told you" meme to secretly tell a Windows-based strain of malware when to grab screenshots from infected PCs, according to security firm Trend Micro.
SEE ALSO: Why every super paranoid internet user needs a cheap ChromebookAlthough the internet meme look like an ordinary digital image, a simple command is hidden in the file's metadata, Trend Micro VP Mark Nunnikhoven says. The malware, on other hand, has been designed to look up the hacker's Twitter account and scan image files for the secret commands.
"The messages used for this malware are very small (typically one word) meaning that they can be hidden between the metadata and actual pixel layout without changing the image itself," Nunnikhoven said in an email.
The hacker appears to have only posted two malicious memes — on Oct. 25 and 26 — with the command "/print," which will order infected Windows PCs to take a screenshot. Other hidden commands the hacker could've sent through the memes include "/clip" to capture clipboard copied content, and "/processos" to retrieve a list of running processes over the PC.
The practice of concealing messaging in nontext files such as images or video is called steganography, and it's become an effective way for hackers to sneak malicious code onto people's computers or send hidden commands over the open web.
"Most networking monitoring programs won't notice anything odd about access to Twitter.com," Nunnikhoven added. "A site that's based around a timeline like Twitter also allows the attacker to sequence commands for the malware. This can be an effective way of building a solid command and control channel."
The good news is that Twitter has disabled the hacker's account on its platform. But it isn't clear how the mysterious attacker was circulating the malware, a Trojanized .exe file.
In response to Trend Micro's findings, Twitter told PCMag: "Keeping people safe and secure on Twitter is our top priority. If content on Twitter is used for malicious purposes, we take action and remove it. Twitter plays no part in the distribution of the malware involved in this campaign."
However, the company didn't address questions over what Twitter can do to stop similar meme-based malware schemes in the future. Meanwhile, others have shown you can cram a whole lot of data, include ZIP archives, inside an image on Twitter, raising the possibility that hackers could employ the same tactic again.
Copyright © 2023 Powered by
Hacker uses internet meme to send hidden commands to malware-声闻过情网
sitemap
文章
75
浏览
242
获赞
53
Twitter flags another Trump tweet for 'abusive behavior'
The dam has broken. Twitter once again slapped a label on a Donald Trump tweet Tuesday, writing thatJ.K. Rowling receives Donald Trump newsletter and her response was as scathing as you'd expect
Some people might be happy with the offer of a limited edition Donald Trump coin, but J.K. Rowling iInstagram proudly highlights how limited organic reach has become
When announcing a new product, it make sense to include testimonials from customers who rave about hCheck out this flying jet board from France's Bastille Day parade
On this day 230 years ago, hundreds of French civilians stormed the military prison known as the BasACLU warns that 'no replies' on Twitter could violate the constitution
Trump was basically Obama's reply guy throughout the 2010s, so it's only fitting that he won't be abTesla's federal tax credit dropped, but other EVs still have the full amount
To anyone dreaming of buying a Tesla electric vehicle: Your timing is terrible.Today is July 1, andThe Moto Z4 lets you go 5G on the cheap
There's a new Moto phone in town, and it lets you go 5G without spending a ton of money. The Moto Z4If 'Sex and the City' starred Jeff Goldblum in every role
Mr. Big better hold onto his cufflinks because there's a new Carrie Bradshaw shopping around town anApple could debut its new laptop chip in a Macbook Pro this year
A few weeks after Apple announced it would start developing its own silicon chip for Mac computers,Instagram makes it easier to take back hacked accounts
Instagram is finally addressing a huge problem on its platform: hacked accounts. The company says itBrits are celebrating the 6
How time flies. Almost as fast as a bunch of deer being chased by a labrador.SEE ALSO:Kellyanne Conway said Trump empowers women and you can guess how that went
When you think of Donald Trump you immediately think of all he's done to make women feel empowered,Here's why everyone's mad about Kylie Jenner's new walnut scrub
Kylie Jenner announced her new skincare line, Kylie Skin, on Tuesday. The collection includes six pr5 weird ways to get around this summer
If you thought an electric scooter was an outlandish way to travel, you better hold on — you hCheck out these stunning winners of the 2019 iPhone Photography Awards
I don't know if you've heard, but iPhone cameras have gotten really good. Like, reallygood. Nowhere