Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.
Security Response

Mass-Mailing Worm in Fake Twitter Account Invite

Created: 17 Jun 2009 22:22:19 GMT • Updated: 23 Jan 2014 18:34:40 GMT
Sammy Chu's picture
0 0 Votes
Login to vote

Last month we reported that spammers had used Twitter as bait to lure innocent victims into a phishing trap, and now we’re seeing a wave of fake Twitter invitations that come carrying a mass-mailing worm. The observed messages appear as if they have been sent from a Twitter account; however, unlike a legitimate Twitter message, there is no invitation URL present in the body. Instead, the user will see an attachment that appears as a .zip file that purportedly contains an invitation card.

Invitation is the name of the malicious attachment, and it is being identified as W32.Ackantta.B@mm, which was first discovered in an e-card virus attack in February. W32.Ackantta.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer and spreads by copying itself to removable drives and shared folders.

Here is what the message looks like in an inbox:

And here is a sample header:

Subject: Your friend invited you to twitter!

As Twitter continues to gain popularity among social networking users, people are regularly receiving invitations and email updates from fellow users. We expect that spammers will continue to use Twitter and other popular social networks as bait in their attacks.