Cybercriminals Use Malicious Memes That Communicate with Malware
blog.trendmicro.com
blog.trendmicro.com
It's pretty clever, because the malware needn't even necessarily be checking the same account over and over: a DGA-style[0] approach could be used, in which the malware checks a different account each day (or hour, or whatever).
Twitter has some options to find this sort of thing, of course, but malware authors have some options to more-cleverly hide data, too. Encoding raw text in an image is easy, and easily-found; encrypted (and hence random-looking) data is harder to detect. Re-encoding images can destroy some sorts of hidden data, but not others (e.g. lossy encoding will likely destroy data encoded on low bits, but information encoded as large swaths of light or dark is less likely to be lost).
Error coding could even be used to make the data more resistant to loss. I don't know if there's a good way to make data all of resistant to loss, encrypted and hidden though: seems like the structure of error coding would make it detectable, while a high-apparent-entropy code would be more susceptible to unrecoverable errors. But I'm not an expert in the field.
Those are just my off-the-cuff thoughts; someone is an expert no doubt has better thoughts to share.
0: https://en.wikipedia.org/wiki/Domain_generation_algorithm
If I download one of these images, which appears to embed CSharp Winform code, how does it actually run within the system?
I suppose it couldn't unless taking advantage of some other exploit along the way. And if that is the case, this article is perhaps a little incomplete.
The memes contain an embedded command that is parsed by the malware after it’s downloaded from the malicious Twitter account onto the victim’s machine, acting as a C&C service for the already-placed malware. It should be noted that the malware was not downloaded from Twitter and that we did not observe what specific mechanism was used to deliver the malware to its victims.
Having its background polling look like a typical Twitter user agent would help it remain hidden and ensure that its command channel is not blocked. (At least for a large class of victims who do not have severe network restrictions in effect.)
You could also send the destination address via Twitter, so that the malware does not leak information about the controller ahead of its activation or so that the controller can make last minute arrangements of temporary resources...