Twitter users under attack again

By on
Twitter users under attack again

Security experts are warning Twitter users of yet another phishing attack, aimed at stealing the usernames and passwords of those signed up to the site.

The malicious tweets in question take the form of a message such as “LOL. this is me??” or “LOL, this is funny?” followed by a link including the term “bzpharma.net”, which leads to a fake user log in page.

If users then enter their credentials on this fake site, they are then shown a fake Twitter “fail whale” before being taken back to the real Twitter main page, so they may not realise their credentials have been compromised, warned Sophos senior technology consultant, Graham Cluley.

Although Twitter staff are warning that the phishing messages are being sent by direct message only, however, Cluley warned that they are also being posted in public fields.

“It appears what is happening is that the messages are being shared more widely because of third-party services like GroupTweet which extend the standard Twitter direct message (DM) functionality and allow private messages to be sent to multiple users *and* optionally made public,” Cluley wrote.

“As a result we have found Twitter accounts that have warned their followers about the phishing attack, only to subsequently fall victim to it themselves.”

Cluley advised any users tricked into handing over their credentials to change their username and password immediately.

Sophos’ latest annual threat report found a whopping 70 per cent rise in the number of spam and malware attacks taking place on social networking sites over the past year.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Log in

Email:
Password:
  |  Forgot your password?