Home Phishing Avoid The 'When Did You Make This Video?' Twitter Direct Message Phishing Attack

Avoid The 'When Did You Make This Video?' Twitter Direct Message Phishing Attack

Posted: September 6, 2011

A new form of phishing attack that targets Twitter users has been caught by SpywareRemove.com malware analysts, This phishing attack utilizes DMs (AKA Direct Messages) that appear to be from friends, along with obfuscated links to phishing websites. Because this phishing attack uses compromised Twitter accounts, you should take care to use strong usernames and passwords to avoid any account break-ins and be ready to change this information if you've become a victim of such a phishing attack. Even though the website that this DM phishing message links you to appears to be Twitter-affiliated, this website should be considered malicious and must, at all costs, be avoided to keep your Twitter account safe.

The Phishing Link with a Hidden Agenda (and URL!)

This recent phishing attack is distributed via already-compromised Twitter accounts; this allows the attack to spread easily, since you may automatically trust any link that's been sent by a social contact. However, this DM-based attack can be easily recognized, since SpywareRemove.com malware researchers have, so far, found that it always uses the following message:

When did you make this video? its hilarious, cant stop laughing lol [Malicious URL]

The URL that's provided is obfuscated by typical link-shortening techniques that make the link's destination unclear. If you make the mistake of interacting with this 'When did you make this video? its hilarious, cant stop laughing lol' link, you'll find that you've been redirected to a fake Twitter login page that resembles the real thing in every way but one – the URL, which is itwitier.com/login/sessions/ instead of Twitter's own twitter.com. This is the only clue you have, before you give up your Twitter login information to criminals. SpywareRemove.com malware experts also note that itwitier.com may also use browser exploits and script-based attacks to install malicious software, so any contact with itwitier.com or the 'When did you make this video? its hilarious, cant stop laughing lol' message should be responded to with an appropriate anti-malware software scan.

Recovering from Being Twitter-Phished

If you suspect that your account has been compromised by the itwitier.com phishing scam, you should immediately change all Twitter login-related information. This will prevent your account from being hijacked in the form of a platform to launch DM phishing attacks at all of your social contacts. You should also contact any friends whose accounts have sent the 'When did you make this video? its hilarious, cant stop laughing lol' phishing link so that they can enact the same precautions.

Other cautionary measures that can be of use include using secure web-browsing settings, keeping your web browser and other forms of software up-to-date and disabling scripts for websites that you don't trust. All of these in conjunction will serve to minimize the vulnerabilities that can be exploited by itwitier.com phishers and other phishing scams.

As long as you take this step, as well as scanning your PC for any potential infections that itwitier.com may have installed onto your PC, it's unlikely that any further harm from this phishing scam will occur.

Loading...