{"id":3763,"date":"2012-03-08T09:44:57","date_gmt":"2012-03-08T17:44:57","guid":{"rendered":"http:\/\/blog.intego.com\/?p=3763"},"modified":"2016-02-12T10:13:46","modified_gmt":"2016-02-12T18:13:46","slug":"flashback-malware-new-variant-changes-twitter-hashtags","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/","title":{"rendered":"Flashback Malware: New Variant Changes Twitter Hashtags"},"content":{"rendered":"<p>We recently reported on how the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/flashback-mac-malware-uses-twitter-as-command-and-control-center\/\">Flashback malware was using Twitter as a command and control center<\/a>, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings.<!--more--> The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it checked, but we have yet to find any actual tweets containing them.<\/p>\n<p>After our blog post, the latest variant contains a slightly different correspondence table. One letter in most of the four-letter codes has changed, and one is the same. Here are the new codes:<\/p>\n<table class=\"flashback-code\">\n<tbody>\n<tr>\n<td class=\"number-a\">0<\/td>\n<td class=\"code-a\">gsqj<\/td>\n<td class=\"number-b\">18<\/td>\n<td class=\"code-b\">kddd<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">1<\/td>\n<td class=\"code-a\">dljt<\/td>\n<td class=\"number-b\">19<\/td>\n<td class=\"code-b\">neal<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">2<\/td>\n<td class=\"code-a\">yxad<\/td>\n<td class=\"number-b\">20<\/td>\n<td class=\"code-b\">hcca<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">3<\/td>\n<td class=\"code-a\">kpdh<\/td>\n<td class=\"number-b\">21<\/td>\n<td class=\"code-b\">dqzo<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">4<\/td>\n<td class=\"code-a\">izaw<\/td>\n<td class=\"number-b\">22<\/td>\n<td class=\"code-b\">kxag<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">5<\/td>\n<td class=\"code-a\">pepb<\/td>\n<td class=\"number-b\">23<\/td>\n<td class=\"code-b\">vpqt<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">6<\/td>\n<td class=\"code-a\">ezvn<\/td>\n<td class=\"number-b\">24<\/td>\n<td class=\"code-b\">wdld<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">7<\/td>\n<td class=\"code-a\">hwbd<\/td>\n<td class=\"number-b\">25<\/td>\n<td class=\"code-b\">nsiy<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">8<\/td>\n<td class=\"code-a\">d2ir<\/td>\n<td class=\"number-b\">26<\/td>\n<td class=\"code-b\">mlvo<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">9<\/td>\n<td class=\"code-a\">rnep<\/td>\n<td class=\"number-b\">27<\/td>\n<td class=\"code-b\">rdel<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">10<\/td>\n<td class=\"code-a\">uqdw<\/td>\n<td class=\"number-b\">28<\/td>\n<td class=\"code-b\">zdxl<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">11<\/td>\n<td class=\"code-a\">jfng<\/td>\n<td class=\"number-b\">29<\/td>\n<td class=\"code-b\">dlno<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">12<\/td>\n<td class=\"code-a\">xloa<\/td>\n<td class=\"number-b\">30<\/td>\n<td class=\"code-b\">bcti<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">13<\/td>\n<td class=\"code-a\">rpdg<\/td>\n<td class=\"number-b\">31<\/td>\n<td class=\"code-b\">eoof<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">14<\/td>\n<td class=\"code-a\">aefl<\/td>\n<td class=\"number-b\">32<\/td>\n<td class=\"code-b\">msan<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">15<\/td>\n<td class=\"code-a\">ocur<\/td>\n<td class=\"number-b\">33<\/td>\n<td class=\"code-b\">xlco<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">16<\/td>\n<td class=\"code-a\">dppu<\/td>\n<td class=\"number-b\">34<\/td>\n<td class=\"code-b\">jsiq<\/td>\n<\/tr>\n<tr>\n<td class=\"number-a\">17<\/td>\n<td class=\"code-a\">jeuv<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We&#8217;re certain that this change was made because we published the previous codes. We will continue publishing them each time we find new codes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings.<\/p>\n","protected":false},"author":3,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190],"tags":[153,1939,86,134],"class_list":["post-3763","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","tag-flashback","tag-hashtags","tag-mac-malware","tag-twitter"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Peter James\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Flashback Malware: New Variant Changes Twitter Hashtags\" \/>\n\t\t<meta property=\"og:description\" content=\"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2012-03-08T17:44:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2016-02-12T18:13:46+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Flashback Malware: New Variant Changes Twitter Hashtags\" \/>\n\t\t<meta name=\"twitter:description\" content=\"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#blogposting\",\"name\":\"Flashback Malware: New Variant Changes Twitter Hashtags\",\"headline\":\"Flashback Malware: New Variant Changes Twitter Hashtags\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/peter\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"width\":400,\"height\":260},\"datePublished\":\"2012-03-08T09:44:57-08:00\",\"dateModified\":\"2016-02-12T10:13:46-08:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#webpage\"},\"articleSection\":\"Malware, Flashback, Hashtags, Malware, X (Twitter)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"position\":2,\"name\":\"Malware\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#listItem\",\"name\":\"Flashback Malware: New Variant Changes Twitter Hashtags\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#listItem\",\"position\":3,\"name\":\"Flashback Malware: New Variant Changes Twitter Hashtags\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/peter\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/peter\\\/\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/02040a1b56c0554236733a69e59ffeacde3aff8b1d8fb9818a2b71ebbc0e2484?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Peter James\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/\",\"name\":\"Flashback Malware: New Variant Changes Twitter Hashtags\",\"description\":\"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/peter\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/peter\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2012\\\/12\\\/MalwareAlert.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#mainImage\",\"width\":400,\"height\":260},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/flashback-malware-new-variant-changes-twitter-hashtags\\\/#mainImage\"},\"datePublished\":\"2012-03-08T09:44:57-08:00\",\"dateModified\":\"2016-02-12T10:13:46-08:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Flashback Malware: New Variant Changes Twitter Hashtags<\/title>\n\n","aioseo_head_json":{"title":"Flashback Malware: New Variant Changes Twitter Hashtags","description":"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#blogposting","name":"Flashback Malware: New Variant Changes Twitter Hashtags","headline":"Flashback Malware: New Variant Changes Twitter Hashtags","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":400,"height":260},"datePublished":"2012-03-08T09:44:57-08:00","dateModified":"2016-02-12T10:13:46-08:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#webpage"},"articleSection":"Malware, Flashback, Hashtags, Malware, X (Twitter)"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","position":2,"name":"Malware","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#listItem","name":"Flashback Malware: New Variant Changes Twitter Hashtags"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#listItem","position":3,"name":"Flashback Malware: New Variant Changes Twitter Hashtags","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/02040a1b56c0554236733a69e59ffeacde3aff8b1d8fb9818a2b71ebbc0e2484?s=96&d=mm&r=g","width":96,"height":96,"caption":"Peter James"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/","name":"Flashback Malware: New Variant Changes Twitter Hashtags","description":"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#mainImage","width":400,"height":260},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/#mainImage"},"datePublished":"2012-03-08T09:44:57-08:00","dateModified":"2016-02-12T10:13:46-08:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Flashback Malware: New Variant Changes Twitter Hashtags","og:description":"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it","og:url":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/","article:published_time":"2012-03-08T17:44:57+00:00","article:modified_time":"2016-02-12T18:13:46+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Flashback Malware: New Variant Changes Twitter Hashtags","twitter:description":"We recently reported on how the Flashback malware was using Twitter as a command and control center, using a correspondence table between dates and four-letter strings, combining them to make twelve-letter strings. The malware sends HTTP requests to Twitter ever hour, searching for these hashtags, and only those tweets posted since the last time it","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"3763","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 17:42:50","created":"2026-09-03 17:42:50","updated":"2026-09-04 11:54:15","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" title=\"Malware\">Malware<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tFlashback Malware: New Variant Changes Twitter Hashtags\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Malware","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/"},{"label":"Flashback Malware: New Variant Changes Twitter Hashtags","link":"https:\/\/www.intego.com\/mac-security-blog\/flashback-malware-new-variant-changes-twitter-hashtags\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=3763"}],"version-history":[{"count":3,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3763\/revisions"}],"predecessor-version":[{"id":4348,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3763\/revisions\/4348"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=3763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=3763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=3763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}