{"id":326666,"date":"2017-06-09T06:36:43","date_gmt":"2017-06-09T06:36:43","guid":{"rendered":"http:\/\/citifmonline.com\/?p=326666"},"modified":"2017-06-09T06:36:43","modified_gmt":"2017-06-09T06:36:43","slug":"malware-planted-in-britney-spears-instagram-page","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/","title":{"rendered":"Malware planted in Britney Spears’ Instagram page"},"content":{"rendered":"

The comments section of Britney Spears’ Instagram account has been used by cyber-thieves to co-ordinate attacks.<\/p>\n

Security firm Eset found the gang controlled its malware, called Turla, by posting comments about images in the singer’s gallery.<\/p>\n

The comments looked like spam but once transformed by code in the virus, directed victims to other sites.<\/p>\n

Several other compromised websites were also being used to track victims and spread the malware.<\/p>\n

Digital detective work<\/strong><\/p>\n

Turla has been active since 2014 and sought to catch out government workers, diplomats and other officials, said Eset researcher Jean-Ian Boutin. It is believed to be run by a hacker group working for the Russian state.<\/p>\n

Most often, he said, Turla’s handlers compromised websites that targets would be likely to visit.<\/p>\n

One compromised server asked visitors to install a booby-trapped extension for the Firefox web browser.<\/p>\n

Digital detective work by Mr Boutin revealed that the command and control (C&C) channel set up between the creators of the extension and victims’ machines was on the singer’s Instagram page.<\/p>\n

The malicious extension searched for comments that, when digitally transformed, matched a specific value. These were then converted into a website address that the compromised machine visited to report in or to update the malicious code they harboured.<\/p>\n

Very few comments posted to the Instagram account had the key characteristics – suggesting that Turla’s creators were testing or refining the control system.<\/p>\n

Mr Boutin said using social media in this way made “life harder for defenders”.<\/p>\n

“Firstly, it is difficult to distinguish malicious traffic to social media from legitimate traffic,” he wrote. “Secondly, it gives the attackers more flexibility when it comes to changing the C&C address as well as erasing all traces of it.”<\/p>\n

Mr Boutin added that he had been in touch with Mozilla, which was working on ways to stop extensions for Firefox being compromised in this way.<\/p>\n

–<\/p>\n

Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"

The comments section of Britney Spears’ Instagram account has been used by cyber-thieves to co-ordinate attacks. Security firm Eset found the gang controlled its malware, called Turla, by posting comments about images in the singer’s gallery. The comments looked like spam but once transformed by code in the virus, directed victims to other sites. Several […]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[106],"tags":[8013,5928,7083],"yoast_head":"\nMalware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"og:description\" content=\"The comments section of Britney Spears’ Instagram account has been used by cyber-thieves to co-ordinate attacks. Security firm Eset found the gang controlled its malware, called Turla, by posting comments about images in the singer’s gallery. The comments looked like spam but once transformed by code in the virus, directed victims to other sites. Several […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/\" \/>\n<meta property=\"og:site_name\" content=\"Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/citi97.3\" \/>\n<meta property=\"article:published_time\" content=\"2017-06-09T06:36:43+00:00\" \/>\n<meta name=\"author\" content=\"Kojo Akoto Boateng\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@citi973\" \/>\n<meta name=\"twitter:site\" content=\"@citi973\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kojo Akoto Boateng\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/\",\"url\":\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/\",\"name\":\"Malware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always\",\"isPartOf\":{\"@id\":\"https:\/\/citifmonline.com\/#website\"},\"datePublished\":\"2017-06-09T06:36:43+00:00\",\"dateModified\":\"2017-06-09T06:36:43+00:00\",\"author\":{\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\"},\"breadcrumb\":{\"@id\":\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citifmonline.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware planted in Britney Spears’ Instagram page\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citifmonline.com\/#website\",\"url\":\"https:\/\/citifmonline.com\/\",\"name\":\"Citi 97.3 FM - Relevant Radio. Always\",\"description\":\"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citifmonline.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\",\"name\":\"Kojo Akoto Boateng\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"caption\":\"Kojo Akoto Boateng\"},\"url\":\"https:\/\/citifmonline.com\/author\/kojo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/","og_locale":"en_US","og_type":"article","og_title":"Malware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always","og_description":"The comments section of Britney Spears’ Instagram account has been used by cyber-thieves to co-ordinate attacks. Security firm Eset found the gang controlled its malware, called Turla, by posting comments about images in the singer’s gallery. The comments looked like spam but once transformed by code in the virus, directed victims to other sites. Several […]","og_url":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/","og_site_name":"Citi 97.3 FM - Relevant Radio. Always","article_publisher":"https:\/\/www.facebook.com\/citi97.3","article_published_time":"2017-06-09T06:36:43+00:00","author":"Kojo Akoto Boateng","twitter_card":"summary_large_image","twitter_creator":"@citi973","twitter_site":"@citi973","twitter_misc":{"Written by":"Kojo Akoto Boateng","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/","url":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/","name":"Malware planted in Britney Spears' Instagram page - Citi 97.3 FM - Relevant Radio. Always","isPartOf":{"@id":"https:\/\/citifmonline.com\/#website"},"datePublished":"2017-06-09T06:36:43+00:00","dateModified":"2017-06-09T06:36:43+00:00","author":{"@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1"},"breadcrumb":{"@id":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/citifmonline.com\/2017\/06\/malware-planted-in-britney-spears-instagram-page\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citifmonline.com\/"},{"@type":"ListItem","position":2,"name":"Malware planted in Britney Spears’ Instagram page"}]},{"@type":"WebSite","@id":"https:\/\/citifmonline.com\/#website","url":"https:\/\/citifmonline.com\/","name":"Citi 97.3 FM - Relevant Radio. Always","description":"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citifmonline.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1","name":"Kojo Akoto Boateng","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","caption":"Kojo Akoto Boateng"},"url":"https:\/\/citifmonline.com\/author\/kojo\/"}]}},"_links":{"self":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/326666"}],"collection":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/comments?post=326666"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/326666\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/media?parent=326666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/categories?post=326666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/tags?post=326666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}