Newsletters
The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Network Security Viruses & Malware Hackers Security Solutions More Topics...
APC Free White Paper
Optimize your network investment &
Enter to win a Samsung Galaxy Note

www.apc.com
Viruses & Malware
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Some Twitter Direct Messages Link to Malware
Some Twitter Direct Messages Link to Malware

By Jennifer LeClaire
September 25, 2012 2:25PM

Bookmark and Share
"Quite how users' Twitter accounts became compromised to send the malicious DMs in the first place isn't clear, but the attack underlines the importance of not automatically clicking on a link just because it appeared to be sent to you by a trusted friend," said security researcher Graham Cluley. A supposed Flash update is really a backdoor Trojan.
 


Be careful when you open that Twitter Direct Message suggesting you've been caught in a Facebook video. It could contain links to a nasty surprise in the form of malware.

Specifically, one of the messages says, "your in this" and has a link to a Facebook video. Another message that works to accomplish the same goal says, "you even see him taping you...that's awful" with a link to the video.

"Users who click on the link are greeted with what appears to be a video player and a warning message that 'An update to Youtube player is needed.' The Web page continues to claim that it will install an update to Flash Player 10.1 onto your computer," said Graham Cluley, a senior security analyst at Sophos.

Where's the Compromise?

Cluley said potential victims are invited to download a program called FlashPlayerV10.1.57.108.exe. He described it as a backdoor Trojan that can also copy itself to accessible drives and network shares.

"Quite how users' Twitter accounts became compromised to send the malicious DMs in the first place isn't clear, but the attack underlines the importance of not automatically clicking on a link just because it appeared to be sent to you by a trusted friend," Cluley said.

"If you do find that it was your Twitter account sending out the messages, the sensible course of action is to assume the worst, change your password -- make sure it is something unique, hard-to-guess and hard-to-crack -- and revoke permissions of any suspicious applications that have access to your account."

Trust Issues

Rob Enderle, principal analyst at the Enderle Group, said the issue boils down to trust.

"What happens is you get a note from somebody that you trust and you believe the note is from them. Often since you are using Twitter and you are multitasking, you click on it before you fully realize that it is likely malware. The damage, of course, is already done," Enderle told us.

Even though he knows better, Enderle admits that he sometimes clicks links he shouldn't. His security programs tend to catch the malware and rid his computer of it. His advice: If you get a message from a company that should know you and it opens with a formal greeting without your name, don't read it because chances are it's malware.

"The malware writers are social engineering," he said. "They recognize that we are all pressed with many things and we are conditioned to trust certain people. If we see something questionable from somebody we trust, we are still likely to trust it, particularly if we are multitasking."
 

Tell Us What You Think
Comment:

Name:



Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.


 Viruses & Malware
1.   Malware Targets Facebook Users
2.   OpenSSL Calls for More Support
3.   How, Why Heartbleed Got Its Name
4.   Android Apps Mine Virtual Currency
5.   Spyware Targets U.S. and Europe


advertisement
Malware Targets Facebook Users
iBanking app spys on communications.
Average Rating:
Android Apps Mine Virtual Currency
Malware drains mobile phone battery.
Average Rating:
OpenSSL Calls for More Support
To find, fix problems like Heartbleed.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Heartbleed Could Cost Millions, Could Have Been Prevented
Early estimates of Heartbleed’s cost to enterprises are running in the millions. The reason: revoking all the SSL certificates the bug exposed will come at a very hefty price. Some say it all could have been avoided.
 
Michaels Says Nearly 3M Credit, Debit Cards Breached
Arts and crafts retail giant Michaels Stores has confirmed that a data breach at its POS terminals from May 2013 to Jan. 2014 may have exposed nearly 3 million customer credit and debit cards.
 
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
The innovative headpiece may find its niche in markets where hands-free access to data can be a big advantage. Glass experiments for doctors are already under way, with some promising results.
 

Mobile Technology Spotlight
Review: Siri-Like Cortana Fills Windows Phone Gap
With the new Cortana virtual assistant, Windows catches up with Apple's iOS and Google's Android in a major way, taking some of the best parts of Apple's and Google's virtual assistants, with new tools too.
 
With Galaxy S5, Samsung Proves Less Can Be More
Samsung has produced the most formidable rival yet to the iPhone 5s: the Galaxy S5. The device is the fifth edition of the company's successful line of Galaxy S smartphones, and shows less can be more.
 
Facebook Rolls Out Potentially Intrusive Location-Sharing
Looking for friends? Facebook users in the U.S. will soon be able to see which of their friends are nearby, using a smartphone's GPS. Could be a cool feature in some cases, or way too much information.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Hackers | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.