3 ms·
Is this not a waste of resources? the malware creators could open a twitter account and post commands directly using established and apparently inocuous phrases
by robarr 8y ago
Is this not a waste of resources? the malware creators could open a twitter account and post commands directly using established and apparently inocuous phrases or words. tweeting “hi” is not a breach of ToS and is less complicated.
- zeveb 8y agoI think it's because a meme-repeating Twitter account looks more real than one which is randomly saying 'hi' (or whatever) over and over and over. It's pretty clever, because the malware needn't even necessarily be checking the same account over and over: a DGA-style[0] approach could be used, in which the malware checks a different account each day (or hour, or whatever). Twitter has some options to find this sort of thing, of course, but malware authors have some options to more-cleverly hide data, too. Encoding raw text in an image is easy, and easily-found; encrypted (and hence random-looking) data is harder to detect. Re-encoding images can destroy some sorts of hidden data, but not others (e.g. lossy encoding will likely destroy data encoded on low bits, but information encoded as large swaths of light or dark is less likely to be lost). Error coding could even be used to make the data more resistant to loss. I don't know if there's a good way to make data all of resistant to loss, encrypted and hidden though: seems like the structure of error coding would make it detectable, while a high-apparent-entropy code would be more susceptible to unrecoverable errors. But I'm not an expert in the field. Those are just my off-the-cuff thoughts; someone is an expert no doubt has better thoughts to share. 0: https://en.wikipedia.org/wiki/Domain_generation_algorithm https://en.wikipedia.org/wiki/Domain_generation_algorithm