Britney Spears' Instagram Photo Hosts Russian Malware Link in Comments: Report

Advertisement
By Shubham Verma | Updated: 8 June 2017 18:26 IST
Highlights
  • Britney Spears' Instagram photo had a malware-laden comment
  • Researchers have broken down the steps it'd require to operate
  • The malware was hidden in a Firefox extension

In the wake of multiple cyber-attacks happening around the globe, with WannaCry and Fireball being the latest ones, cyber-security firms and researchers are tirelessly upping various methods to discover hacks to curb them or some such. Now, researchers at ESET Security have found a new kind of malware that uses platforms like Instagram to connect to its controllers. It is said to be linked to a Russian group, Turla, which is known to operate a larger cyber espionage network.

The malware was unearthed by ESET Security, a Slovak IT security company. Instagram is popular amongst people who love sharing videos and photos, along with numerous and innocuous comments and likes flooding the photo or video posts. The researchers say the encoded command was masquerading as a normal comment, having tucked itself in plain sight amongst other comments on a Britney Spears Instagram photo. The comment posted by an account named 'asmith2155', with no posts and followers and now deactivated, hid a Web address to be deciphered step-by-step by the actual malware involving a Firefox extension and a JavaScript-based backdoor, reports Popular Mechanics.

Photo Credit: ESET Security/ Britney Spears/ Instagram

Advertisement

However, the steps required to encode it are said to be immensely high-level and incremental in nature. The malware hidden under the Firefox extension would scan the post and turn each comment into a number, known as 'hash'. It will then look for the comments translating to the hash number 183. In this case, the number 183 would match with just one comment that was linked with the encoded command.

Advertisement

Having found the one, the malware will then start looking for particular characters containing hashtags and an invisible 'Zero Width Joiner', which is a code to combine two emoji parts into a single one 'combo-moji'. Post this, it would take the letters to use them to form a Bit.ly link, which will be used by the malware to connect to its controllers. This kind of a method enables the controllers to change the arcane destinations without making any contact with the malware itself. To do that, they just require to delete the original comment and create a new one having the same hash number but a new encoded URL link.

The researchers have further said, "Instead of giving the malware a specific key to a specific lock, programmers told the malware how to find places where keys would be hidden, leaving them free to change either lock or key on a whim." Furthermore, they have also emphasised how the vulnerability of open Internet can be used to an extent where cyber spies can conduct and mask their hacking business.

Advertisement

Incidents of this kind repeatedly iterate the importance of a better and sustainable Internet security paradigm so that our social media profiles elsewhere (like Facebook and Twitter) do not act as a conduit for cyber espionage.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  2. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  3. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  4. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  5. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  6. Vivo X300 FE Launched as Global Version of This Chinese Smartphone
  7. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  8. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  9. Vivo V70 FE Colour Options, Key Features Revealed Ahead of March 9 Launch
  10. Here's When the Xiaomi 17T Could Make Its Way to India
  1. Honor 600 Lite Launched With MediaTek Dimensity 7100 Elite, 6,520mAh Battery: Price, Specifications
  2. Vivo T5x 5G Teased to Launch in India Soon; Company Says AnTuTu Score Exceeds 1 Million Points
  3. MWC 2026: Oppo, MediaTek Join Hands to Showcase New On-Device AI Capabilities for Future Smartphones
  4. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  5. Nubia Neo 5 GT With MediaTek Dimensity 7400 SoC Launched at MWC 2026: Price, Specifications
  6. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices This Year
  7. Google Play Announces New Android Policies With Expanded Billing Options, Eases Access to Third-Party App Stores
  8. Google's NotebookLM Upgraded With Cinematic Video Overviews Feature
  9. Infinix Note 60 Ultra Launched at MWC 2026 With Pininfarina Design, Satellite Calling: Price, Specifications
  10. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.