HomeSecurityPopular chat platforms are being used as C&C servers

Popular chat platforms are used as C&C servers

Trend Micro security researchers put the popular chat and social networking platforms Slack, Discord, Telegram, HipChat, Mattermost, Facebook and Twitter under the microscope to determine whether they can be used by attackers for malicious actions, such as hosting and managing malware, bitcoin mining, data theft, etc. Let's see what the research results showed.

chat - chat

According to Trend Micro, several popular instant messaging services and applications, such as Slack, Discord, and Telegram, can be hijacked by malicious actors and turned into malware command and control (C&C) infrastructures.

It seems that threat actors can get very creative when it comes to Command-and-Control (C&C) communications. Several hacking groups are resorting to Twitter, and as it recently became known, a hacking group linked to Russia hid C&C server addresses in comments posted on Britney Spears' Instagram account.

Trend Micro researchers examined several popular chat platforms and found that many of them can be targeted by cybercriminals, and several are already being used for malicious activities. These applications are a tempting target for cybercriminals, as they are often used for legitimate purposes, making it even more difficult to detect malicious traffic.

The experts analyzed the collaborative tool Slack, the chat app Discord aimed primarily at gamers, the privacy-focused messenger Telegram, the messaging platform HipChat, Mattermost, the open source alternative to Slack, Twitter and Facebook.

Developers of this type of application usually provide various API components that allow interaction with custom and third-party applications (e.g. synchronization with users' calendars to receive notifications directly in the platform interface).

[su_heading]SLACK[/su_heading]

In the case of Slack, the researchers concluded that the platform can be turned into a C&C server, which is however not very practical for large amounts of data, as there is a 5GB upload limit.

Experts created a PoC demonstrating how Slack can be compromised to send commands to a bot, to list directories, upload files, execute system commands, as well as take screenshots and upload them to Slack.

Trend Micro has identified some suspicious files that interact with Slack, as well as some malicious Android apps that exploit Slack to intercept and transmit information to attackers.

[su_heading]DISCORD[/su_heading]

Regarding Discord, researchers found that the platform is being exploited to host malware, including key generators, cracks, exploit kits, and injectors. The platform is also being used for malicious actions related to Bitcoin mining, as well as malware targeting users of the online platform Roblox.

[su_heading]TELEGRAM[/su_heading]

Telegram, despite requiring a valid phone number to create an account, was also found to be vulnerable. A PoC created by Trend Micro shows that the platform can be exploited to execute commands on an infected system and steal data. Telegram is also vulnerable to the TeleBot backdoor and the Telecrypt Ransomware.

[su_heading]HIPCHAT, MATTERMOST, FACEBOOK[/su_heading]

HipChat's API was also found to provide functionality required by malicious C&C servers, while Mattermost appears to be the least attractive to attackers. Facebook can also be compromised, as Zone13 experts recently demonstrated, but Trend Micro points out that the social networking platform has good mechanisms for detecting suspicious activity in its users' accounts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS