Flashback Malware Authors Using Twitter to Talk to Infected Machines - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Flashback Malware Authors Using Twitter to Talk to Infected Machines

by

twitter ios iconWe've been following for some time the story of the Flashback trojan that has been targeting Mac users by masquerading as a Flash Player installer but which has also been evolving to include increasingly sophisticated tactics for infecting users' computers.

Antivirus firm Intego now reports that Flashback's creators are using an interesting new tactic for communicating with machines infected by the trojan: Twitter. According to the report, Flashback is programmed to search Twitter for Tweets containing a unique 12-digit code that changes daily, with the malware's authors being able to issue commands to infected computers by posting from any number of Twitter accounts simply by including the appropriate code as a hashtag.

These hashtags aren’t as simple as, say, #Flashback or #MacMalwareMaster, but are seemingly random strings of characters that change each day. Intego’s malware research team cracked the 128-bit RC4 encryption used for Flashback’s code and discovered the keys to this system.

The hashtags are made up of twelve characters. There are four characters for the day, four characters for the month, and four characters for the year. [...]

So, for today, March 5, 2012, the hashtag would be #pepbyfadxeoa.

Intego is monitoring Twitter to look for any commands being issued using the hashtag codes, also noting that Flashback uses a number of different user agent strings in its web queries looking for the Twitter contacts, seeking to avoid detection and removal.

Top Rated Comments

GGJstudios Avatar
190 months ago
I just upgraded my gfs flashplayer last week ... What are the chances that it's this Trojan ?? How can I check?
Go to your /Users/yourusername/Library/ folder and look to see if you find any of these files:
~/.MacOSX/environment.plist
~/Library/LaunchAgents/com.apple.SystemUI.plist
~/Library/Preferences/perflib
~/Library/Preferences/Preferences.dylib
~/Library/Logs/swlog
If you don't have any of these files, you're not infected.

Your Library folders are hidden by default in Lion. To get to your /Library or /Users/yourusername/Library (also known as the ~/Library) folders in Lion, Launch Finder and click Go > Go to Folder and type: /Library or ~/Library

Here's how to avoid any question:
With my flash player I'm careful. I never click on a pop-up when it tells me it's out of date.

I go to Adobe's site and update there.
This is very important:
To repeat: the vendor has provided no actual evidence that such messages are happening.
In fact, while I may have missed it, I've seen no corroborating evidence supporting the recent reports coming from Intego. I haven't seen any other security firm confirming the presence of these variations, or the variation that supposedly installs itself without user intervention, as they also claim. Until such claims are proven by other companies, I'll continue to find Intego's claims suspicious, at best.

Generally speaking, these reports by security firms are little more than thinly veiled attempts to scare users into buying their security software, which you don't need. However, such reports can be useful reminders for users to continue to practice safe computing.
[LIST=1]
* Make sure your built-in Mac firewall is enabled in System Preferences > Security > Firewall


* Uncheck "Open "safe" files after downloading" in Safari > Preferences > General


* Uncheck "Enable Java" in Safari > Preferences > Security. Leave this unchecked until you visit a trusted site that requires Java, then re-enable only for your visit to that site. (This is not to be confused with JavaScript, which you should leave enabled.)


* Check your DNS settings by reading this (https://guides.macrumors.com/Mac_Virus/Malware_FAQ#Why_am_I_being_redirected_to_other_sites.3F).


* Be careful to only install software from trusted, reputable sites. Never install pirated software. If you're not sure about an app, ask in this forum before installing.


* Never let someone else have physical access to install anything on your Mac.


* Always keep your Mac and application software updated. Use Software Update for your Mac software. For other software, it's safer to get updates from the developer's site or from the menu item "Check for updates", rather than installing from any notification window that pops up while you're surfing the web.

That's all you need to do to keep your Mac completely free of any virus, trojan, spyware, keylogger, or other malware.

You don't need any 3rd party antivirus app to keep your Mac malware-free. Macs are not immune to malware, but no true viruses exist in the wild that can run on Mac OS X, and there never have been any since it was released over 10 years ago. You cannot infect your Mac simply by visiting a website, unzipping a file, opening an email attachment or joining a network. The only malware in the wild that can affect Mac OS X is a handful of trojans, which cannot infect your Mac unless you actively install them, and they can be easily avoided with some basic education, common sense and care in what software you install. Also, Mac OS X Snow Leopard and Lion have anti-malware protection (http://support.apple.com/kb/ht4651) built in, further reducing the need for 3rd party antivirus apps.
Mac Virus/Malware FAQ (https://guides.macrumors.com/Mac_Virus/Malware_FAQ)
Score: 8 Votes (Like | Disagree)
FloatingBones Avatar
190 months ago
The claim is interesting, but a quick search on Twitter doesn't show that #pepbyfadxeoa is actually being used by any program for anything. If the vendor's claim is true, they should be able to tell us a prior hashtag which shows actual nefarious activity.

We are still suffering from Adobe's lax attitudes for security around their products. All of the "Get Flash Player" and "Get Adobe PDF Reader" links that Adobe encouraged in the past have helped foster a lackadaisical attitude towards the clear risk of installing a trojan horse on machines. I will be happy as Flash on the WWW continues to fade into the sunset.

I think this uses twitter even if you don't use it personally, they are just using the open nature of the site as a means to communicate with the malware.
Bingo. If the trojan is actually using twitter as a conduit, it's probably using accounts that were embedded in the trojan. Blocking those would require the blocking of connections to twitter servers with something like Little Snitch (http://www.obdev.at/products/littlesnitch/index.html)
or outbound blocks in your network's firewall.

To repeat: the vendor has provided no actual evidence that such messages are happening. I see no evidence with todays hashtag.

One other note: the Twitter stream is a real cesspool these days. As far as I can tell, Twitter does nothing to automatically remove the 'bot accounts that send out Amazon Associates link-spam. They're also doing nothing to automatically censor accounts that send @mentions that spam the "adult" dating sites. Doesn't Twitter have any friends in the Valley who could help them keep the toxic pollution out of their stream?
Score: 7 Votes (Like | Disagree)
GGJstudios Avatar
190 months ago

Much like life, if you hang around in bars, you can come down with diseases.
So if you don't hang around in bars, you won't catch any diseases???
Score: 6 Votes (Like | Disagree)
FloatingBones Avatar
190 months ago
I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.

I'm even more suspicious when the claimed evidence doesn't pan out. To alter the slogan from that famous Wendy's commercial (https://www.youtube.com/watch?v=Ug75diEyiA0):

Where's the tweets? :D
Score: 5 Votes (Like | Disagree)
190 months ago
I'm always suspicious of anti-virus firms who seem to know very specific details of viruses/malware/trojans.

Word, bro. And what about those pesky "doctors" who seem to know all about illnesses and bacteria and whatnot? Damned scientists!
(Fricking magnets, how do they work?)

----------

Then you can send a message to the hacker how dumb he was. With the same amount of work he had put into this malware he could have created an app and probably made some money.

You mean he has no bussiness plan for this?
Score: 4 Votes (Like | Disagree)
Amazing Iceman Avatar
190 months ago
Nasty!!

(I'm breaking my arm patting myself on the back for my non-involement with social media.)

I do feel bad for the majority of the world who does use social media...this is really lousy.

Much crap on social media, but a tremendous amount of good in places where free expression is only possible through Twitter, etc. It's a powerful tool for many in the world, and any sympathy I might have for certain hackers is totally absent in situations like this.

Well, don't over pad yourself. The infection doesn't come from Twitter, but from a fake Adobe Flash Installer. Twitter is only one of the many ways hackers use to communicate with the hacked Macs.
Score: 3 Votes (Like | Disagree)

Popular Stories

Home Hub Command Center with Dome Base Feature

Apple Smart Home Hub to Feature iMac G4-Style Design

Wednesday September 30, 2026 4:36 am PDT by
Apple's long-rumored smart home hub will have an iMac G4-style design and a host of unique features, Bloomberg's Mark Gurman reports. The smart home hub is said to feature a square 6-inch display, with variants that can be placed on a countertop or mounted on a wall. It features a single FaceTime camera on the front, with microphones and speakers in its connected base. Gurman described the...
HomePod minis on gradient feature 1 1

Three New Apple Smart Home Products Coming on October 13

Wednesday September 30, 2026 4:04 am PDT by
Apple plans to introduce a series of new smart home products on Tuesday, October 13, according to Bloomberg's Mark Gurman. Apple reportedly plans to debut its long-awaited smart home hub device, a new HomePod mini, and a new Apple TV on the date. The new HomePod mini and Apple TV are set to retain their existing designs, but tout faster chips to support Siri AI. The new HomePod mini will...
iphone duo colors

Apple Shares Photos Shot on iPhone Duo

Thursday October 1, 2026 1:37 pm PDT by
Apple on Instagram today shared a curated gallery of six photos shot on the iPhone Duo. The photos were shot by American photographers Jake Michaels and Jason Nocito, as part of a project commissioned by Apple. iPhone Duo is equipped with four cameras:A rear 48-megapixel Fusion Main camera A rear 48-megapixel Ultra Wide camera A front 12-megapixel Center Stage camera in the outer display A...
Latest Stories
Apple Store in UK Reopening on iPhone Duo Launch Day
Apple Store in UK Reopening on iPhone Duo Launch Day
5 minutes ago
AT&T Acknowledges iPhone 18 Pro Max Issues: 'Update Immediately'
AT&T Acknowledges iPhone 18 Pro Max Issues: 'Update Immediately'
11 hours ago
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
16 hours ago
Apple Shares Photos Shot on iPhone Duo
Apple Shares Photos Shot on iPhone Duo
18 hours ago
Apple Says iPhone Duo Has Replaceable 'Cover Layer'
Apple Says iPhone Duo Has Replaceable 'Cover Layer'
19 hours ago
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
21 hours ago
Apple TV Just Updated Its Selection of 'Bonus' Movies
Apple TV Just Updated Its Selection of 'Bonus' Movies
22 hours ago
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
22 hours ago
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
23 hours ago
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
1 day ago
Apple's All-New Home Hub Rumored to Launch in These Four Colors
Apple's All-New Home Hub Rumored to Launch in These Four Colors
1 day ago
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
1 day ago
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
1 day ago
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
1 day ago
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
1 day ago
Microsoft 365 Work Accounts May Stop Syncing in Apple Mail
Microsoft 365 Work Accounts May Stop Syncing in Apple Mail
3 hours ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
2 days ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
2 days ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
2 days ago
Apple Event on October 13?
Apple Event on October 13?
2 days ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
2 days ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
2 days ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
2 days ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
2 days ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
2 days ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
2 days ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
2 days ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
2 days ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
3 days ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
3 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors