Are social networks creating malware mules?

happygeek 1 Tallied Votes 426 Views Share

The latest research from security vendor Symantec would appear to suggest that cybercrime gangs are now applying drug smuggling techniques to their trade, and are actively using 'malware mules' in order to distribute threats within social friendship networks.

According to the latest Internet Security Threat Report, email accounts are now being sold for just 65p on the underground web black market, and these are then used to distribute spam or malware via people’s trusted network of contacts. The advertised prices of email accounts in 2009 ranged between 65p and £13 for each account. Most advertisements listed a flat rate, although some sellers also listed bulk purchase prices such as 30 for £95 or 65p each on bulk purchase. Some advertisements stated that Web space was included with the email account and were listed at higher prices. ISPs often include free Web space along with email accounts as a part of the service, which many people never use. Criminals who compromise these accounts can use the space to host phishing sites or malicious code without the knowledge of the account owner.

These compromised accounts can be used for sending out spam in addition to harvesting additional email addresses from contact lists, taking advantage of the fact that the recipients are likely to trust the validity of a message coming from a known contact.

The stolen personal email account details are advertised on the underground economy on black market forums that are used for the promotion and trade of stolen information and services. What's more, compromised email accounts are also often used to provide access to additional sensitive personal information such as bank account passwords, student identification numbers, mailing addresses and phone numbers as well as passwords to social networking accounts that people often store in saved personal emails. The data could be used to reset passwords, potentially giving the fraudster complete access to personal account and indeed whole identities.

Con Mallon, Security Expert, Symantec, comments: "The growth in sales of email accounts on the underground economy is a worrying trend. If fraudulent purchases are made on your credit card, you’re covered by your lender and can usually recoup the money. However, if your email account is hacked who do you turn to? Scarily, scammers could have access to all your passwords for less than a pound".

Dani AI

Generated

As noted, the underlying problem is trust: social platforms give attackers a ready-made audience and believable context, and hijacked accounts are an easy way to seed malicious links or attachments into real conversations. Security research continues to document thread‑hijacking and the use of compromised accounts to deliver malware rather than rely on mass, anonymous spam. (proofpoint.com)

Practical priorities for individuals and small teams (fast, high‑impact):

  • Turn on multi‑factor authentication everywhere and prefer phishing‑resistant options (security keys / passkeys) where available.
  • Use a reputable password manager and unique passwords; stop reusing email/password combinations.
  • Review and remove unrecognized connected apps, active sessions, and scheduled posts or forwarding rules; revoke tokens that look odd.
  • If an account is sending spam or you see unfamiliar activity, change the password, revoke app access, run an AV/anti‑malware scan on devices, and follow the platform’s recovery flow.
    MFA dramatically reduces automated account takeovers and platform help pages walk through the exact recovery steps. (microsoft.com)

Controls brands and marketers should add (prevention + quick containment):

  • Publish SPF/DKIM and start DMARC monitoring; move to a restrictive policy (quarantine/reject) once legitimate senders are validated.
  • Require SSO with enforced MFA for all staff and page admins, audit page roles regularly, and restrict third‑party apps to an approved list.
  • Keep an incident playbook for hijacked pages (revoke tokens, suspend scheduled posts/ads, rotate keys, notify followers/customers). RFCs and identity guidelines explain these technical controls and deployment steps. (rfc-editor.org)

Note: attackers adapt fast (AiTM/OAuth phishing, MFA fatigue, fake apps and ads), so combine technical controls with regular audits and user awareness training. For a compromised account the immediate checklist above is the best way to stop a hijacked identity from becoming a “malware mule.” (proofpoint.com)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.