Web 2.0 - Twitter Used to Control Data-Stealing Botnet - eWeek Security Watch

Twitter Used to Control Data-Stealing Botnet

Written By
Brian Prince
Brian Prince
Aug 14, 2009
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

It’s been a tough week for Twitter. First DDoS attacks. Now Arbor Networks security researcher Jose Nazario has come across something more troublesome – a botnet using Twitter for its command-and-control.

According to Nazario, the botnet uses the micro-blogging service’s status messages to communicate to compromised machines. The tweets contain obfuscated links to sites with new commands and executables to download and run.

As Twitter has grown in popularity, it has become a source of increasing interest for attackers. Last month for example, Koobface – the worm that made headlines for squiggling around Facebook and MySpace – made an appearance on Twitter.

But using the micro-blogging service as a means to control bots is an interesting twist. In a blog post, Nazario outlines how he unpacked one of the update messages and uncovered hidden links the bot will send data to. Some of the links may be tied to Brazilian cyber-criminals known for banking Trojans.

Nazario wrote that he spotted the rogue account because a bot used the RSS feed to get the status updates.

“It’s an infostealer operation,” he blogged.

The account appears to be one of a handful of Twitter C&C accounts, he added.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.