Facebook and Twitter users take heed: Expect those surges of spam you’ve been experiencing to recur. Hackers and spammers have staked out new turf for attacking the popular social networks, and it’ll take the good guys some time to shore up defenses, cybersecurity experts say.
Here’s what’s happening: Hackers are aggressively probing Twitter and Facebook for security holes, especially ones they can use to tap into mechanisms for rapidly disseminating content to millions of users. On discovering a fresh vulnerability, an attacker will usually disperse a test posting that spreads in wormlike fashion, proving his skill.
Next, alert spamming gangs move into action. They stand ready to blast high volumes of spam through the new hole for as long as it stays unpatched. Often, such spam comes from “clickjackers” who make money by getting users to click to a webpage full of ads, or to an advertising-related survey. They get paid up to $1 a click from advertisers, and can make hundreds of thousands of dollars a day.
Facebook and Twitter “are the new toy everybody wants to attack to get visibility and also to make a little money,” says Catalin Cosoi, research director at anti-virus firm BitDefender.
Spammers pounced all over a flaw recently uncovered in Twitter’s mouse-over feature. Anyone who simply moused over a corrupted microposting, or tweet, caused an identical tainted tweet to be sent to all of his or her followers. Each subsequent click spread the attack exponentially.
Twitter devotes 23 of its 250 employees to security, trust and safety issues, says Twitter security director Bob Lord. The team reacted quickly to users tweeting about the spam surge in progress and patched the hole over the course of six hours. “We work very hard to protect our users, which is at the core of what we do,” says Lord.
Attackers also recently…