A recently discovered piece of malware has a unique way of communicating with its creator—through an internet meme posted on Twitter.
The mysterious hacker has been using the "What if I told you" meme to secretly tell a Windows-based strain of malware when to grab screenshots from infected PCs, according to security firm Trend Micro.
SEE ALSO: Why every super paranoid internet user needs a cheap ChromebookAlthough the internet meme look like an ordinary digital image, a simple command is hidden in the file's metadata, Trend Micro VP Mark Nunnikhoven says. The malware, on other hand, has been designed to look up the hacker's Twitter account and scan image files for the secret commands.
"The messages used for this malware are very small (typically one word) meaning that they can be hidden between the metadata and actual pixel layout without changing the image itself," Nunnikhoven said in an email.
The hacker appears to have only posted two malicious memes — on Oct. 25 and 26 — with the command "/print," which will order infected Windows PCs to take a screenshot. Other hidden commands the hacker could've sent through the memes include "/clip" to capture clipboard copied content, and "/processos" to retrieve a list of running processes over the PC.
The practice of concealing messaging in nontext files such as images or video is called steganography, and it's become an effective way for hackers to sneak malicious code onto people's computers or send hidden commands over the open web.
"Most networking monitoring programs won't notice anything odd about access to Twitter.com," Nunnikhoven added. "A site that's based around a timeline like Twitter also allows the attacker to sequence commands for the malware. This can be an effective way of building a solid command and control channel."
The good news is that Twitter has disabled the hacker's account on its platform. But it isn't clear how the mysterious attacker was circulating the malware, a Trojanized .exe file.
In response to Trend Micro's findings, Twitter told PCMag: "Keeping people safe and secure on Twitter is our top priority. If content on Twitter is used for malicious purposes, we take action and remove it. Twitter plays no part in the distribution of the malware involved in this campaign."
However, the company didn't address questions over what Twitter can do to stop similar meme-based malware schemes in the future. Meanwhile, others have shown you can cram a whole lot of data, include ZIP archives, inside an image on Twitter, raising the possibility that hackers could employ the same tactic again.
Copyright © 2023 Powered by
Hacker uses internet meme to send hidden commands to malware-铁板歌喉网
sitemap
文章
8523
浏览
463
获赞
18456
Cloudflare goes down, and takes the internet's security blanket with it
When Cloudflare has problems, the rest of the internet can't be that far behind. The company whose eApple May 7 event: Last
On May 7, Apple will hold the "Let Loose" livestream, its first official Apple Eventof the year. WhiBest Cyber Monday gift card deals: DoorDash, Instacart, Hulu, live at Amazon, Best Buy, and more
The best Black Friday gift card deals at a glance: BEST OVERALLSpotify Wrapped 2024 arrives: 5 new features to check out
'Tis the season of colorful graphics, embarrassing stats, and personalized data stories! That's righSorry gardeners, you can't buy foreign seeds on Amazon anymore
Amazon has a new rule in place governing seed and plant imports for U.S. customers: Nope.The onlineHow to download Google Maps
Losing your internet connection when trying to navigate isn't a fun moment. Whether you're driving oBest Chromebook deal: Get the Samsung Galaxy Chromebook 2 for $349 at Best Buy
SAVE 50%: As of April 23, get the Samsung Galaxy Chromebook 2 (Intel Core i3, 8GB RAM, 128GB eMMC) fCanva unveils fleet of tools for large organizations
Canva is building on its creative toolkit with a redesigned platform tailored to businesses. The comPortland bans facial recognition tech, despite Amazon's lobbying
The city of Portland just took the fight against facial recognition up a notch. Late Wednesday afterHow to find Amazon Prime Day deals: Turn on Alexa's Amazon deal alerts
Hunting down the best Prime Day sales can be exhausting. Limited-availability Lightning Deals oftenBest headphones deal: $100 off Bose QuietComfort
Save $100:Bose QuietComfort headphones are back down to their lowest price on Amazon — just $2How to download Google Maps
Losing your internet connection when trying to navigate isn't a fun moment. Whether you're driving oAstrology tech can provide a safe space for the LGBTQ community, but there are limitations
Mashable is celebrating Pride Monthby exploring the modern LGBTQ world, from the people who make upBest Lego Cyber Monday deals: Star Wars, succulents, and more
UPDATE: Dec. 1, 2024, 3:05 p.m. EST This post has been updated to reflect the latest pricing on Blac'Hawk Tuah' girl Haliey Welch resurfaces: The internet reacts with jokes, memes.
Haliey Welch, aka the "Hawk Tuah Girl," has resurfaced with a public statement after a controversy o