The remarkable speed with which several worms spread on Twitter on Tuesday may have sent opportunistic spammers scurrying to exploit a quickly patched vulnerability, but cyber criminals looking for ways to hijack PCs essentially steered clear.
[ Twitter knew a month ago about the cross-site scripting bug that led to a series of fast-spreading worms. | Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]
"Social networks have built-in antibodies...their users," said Sean Sullivan of the Finnish security company F-Secure. "Compare the Twitter attack to a malicious attack of yesteryear that took weeks or even months to develop. This peaked and ebbed in two and a half hours," Sullivan said.
That pace was the worms' undoing. Although they spread voraciously for several hours -- the spike of worm-spreading traffic started around 5:30 a.m. Pacific time, according to data from Trendistic.com -- Twitter quashed the bug by 7 a.m.
With users tweeting around the clock somewhere in the world, it's not surprising that the original worm and the inevitable copycats came to the attention of Twitter's security team. "They make a very dynamic feedback loop for Twitter," Sullivan said.
What's not as intuitive is that the fast up-up-up and then the just-as-rapid down-down-down of the infection pulse is something hackers don't want.
"Hard-core hackers won't go after something like Twitter," Sullivan contended, "because it causes too much damage."
Too much, as in too much publicity, and more infections than can be handled.
If the goal is to hijack a PC -- the usual for hackers out to pillage machines of passwords and usernames, or other information that can lead to money -- then the last thing cybercriminals want is for the victims to know they've been nailed. Nor is it efficient to compromise more machines than can be controlled, or launch attacks that attract the instant attention of authorities, security researchers and users.
"This spread to too many people, too fast," Sullivan said. "That's like scorched earth for them." In other words, a barren wasteland.
Instead, the flaws in services like Twitter or Facebook -- the latter was hit with attacks that exploited a pair of vulnerabilities earlier this month -- are tailor-made for scammers, who run short-lived campaigns as a matter of course, hoping to dupe people while the getting's good.