TLDR: malware uses meme images containing hidden instructions posted on Twitter as a way to receive commands. It's one-way communication though - the result of the operation is still uploaded to a C&C server.
Having its background polling look like a typical Twitter user agent would help it remain hidden and ensure that its command channel is not blocked. (At least for a large class of victims who do not have severe network restrictions in effect.)
You could also send the destination address via Twitter, so that the malware does not leak information about the controller ahead of its activation or so that the controller can make last minute arrangements of temporary resources...