Incidents

All about Brittany on Twitter

The day before yesterday, our industry colleagues wrote about how searches on “Brittany Murphy” using search engines brought up sites containing links to malware. So it’s the usual situation, with the bad guys exploiting the death of a famous person, just like they did with Michael Jackson.

Yesterday we identified some Twitter accounts that are being used both to send “make money on the Internet” spam, and also to spread links to malware. In both cases, they used Brittany Murphy’s name.

Here’s a couple of examples:

The actual text of messages of this type can vary. What characterizes them is that the first link is genuine, i.e. it leads to a site which really does talk about the topic tweeted. The second link though, leads to standard spam advertising sites which tell you how to earn money on the Internet, offer various goods, etc.The second type of tweet we’re seeing is undeniably malicious. These tweets, like the first type, use Brittany Murphy’s name, but have a shortened bit.ly URL leading to malware:

Theoretically, all shortened bit.ly URLs get checked to make sure there’s no malware. But in this case it looks as though there’ve been so many that they can’t be processed quickly enough to prevent abuse. The screenshot confirms this – the link was tweeted a day before we found it, and it was still live.

This type of tweet follows the standard pattern: click, and you get redirected to a malicious site:

What’s behind all these videos? Malware, of course: this time, it’s Packed.Win32.Krap.ag. It’s got a backdoor function. It also downloads rogue AV software, which requires the victim to “purchase” it in order to delete “viruses” supposedly detected on the machine.

At the time I was putting this blog together, there were 6,950,994,912 tweets about the death of Brittany Murphy. And lots of Twitter users are retweeting the bad guys’ messages, meaning that the number of malicious tweets (and the number of potential victims) is only going to grow.

To sum up, Brittany Murphy’s death is currently being exploited by cybercriminals in two ways:

  1. To send spam linking to sites offering a range of goods and services
  2. To spread malware

So please be very, very cautious when you’re searching Twitter (or any other social network) for news about Brittany Murphy. The hot topic of the day is always going to be exploited by cybercriminals, but you can make things more difficult for them: don’t click on short URLs, and even more important, don’t retweet suspicious looking messages to your followers.

All about Brittany on Twitter

Your email address will not be published. Required fields are marked *

 

Reports

Operation TunnelSnake

A newly discovered rootkit that we dub ‘Moriya’ is used by an unknown actor to deploy passive backdoors on public facing servers, facilitating the creation of a covert C&C communication channel through which they can be silently controlled. The victims are located in Africa, South and South-East Asia.

APT trends report Q1 2021

This report highlights significant events related to advanced persistent threat (APT) activity observed in Q1 2021. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports.

The leap of a Cycldek-related threat actor

The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.

Subscribe to our weekly e-mails

The hottest research right in your inbox