3 ms·
Its unlikely, but this reminds of this story [1], where hackers used public posts on Twitter to send commands to a botnet. Kind of genius, as it doesn't matter
by gitgud 4y ago
Its unlikely, but this reminds of this story [1], where hackers used public posts on Twitter to send commands to a botnet.
Kind of genius, as it doesn't matter what the user is, and becomes impossible to track or prevent messages being relayed to some botnet somewhere.
These could be encrypted messages like that... Or it could just be a glitch in a spam bot...
[1] https://www.darkreading.com/endpoint/tool-controls-botnet-with-twitter-direct-messages https://www.darkreading.com/endpoint/tool-controls-botnet-wi...
- shanebellone 4y agoRecently I've been playing with a GSM modem to send and consume SMS programmatically. It's simple to echo a CLI command and response over SMS with burner sims. I immediately wondered if hackers were using this approach for command and control.
- red-iron-pine 4y agoThey definitely do, with real life exploits using pastebin or reddit as ways to post C2 code. Effective, because you can post it as HTTP/HTTPS traffic that generally flies under the radar of a lot of IDS/IPS systems. Even if they inspect the packet it's just a buncha random reddit gibberish and you could use memes as commands, e.g. "I also choose this guy's wife" == launch attack
- GrinningFool 4y agoIn a similar vein - blog comments as distributed filesystem.
- fIREpOK 4y ago> Kind of genius, as it doesn't matter what the user is It's a good way to avoid tracking of your meta data too for legitimate encrypted messages.
- skylanh 4y agoThis was an issue decades (oof) ago with IRC and other public forums. C&C through a third party. The issue as I recall is that the IRC moderation tools didn't allow shutting down the various channels quickly enough or quickly banning connected clients without also affecting legitimate users' expectation of how IRC worked. Might have been EFNet.