You are here: Home // Featured Posts, Social Networking, Twitter // Beware: LOL Phishing Scam Still Circulating on Twitter and Turning into a Spam Wave (Video)

Beware: LOL Phishing Scam Still Circulating on Twitter and Turning into a Spam Wave (Video)








Video of Twitter Phishing: The BZPharma ‘LOL this is funny’ Attack

A phishing attack that began striking U.S. Twitter profiles last weekend is still going strong and isn’t showing any signs of letting up. As VentureBeat reports, the scam operates through a direct message reading, “Lol. this you?” Once users click on it, they’re sent to a fake Twitter login page, where they could be tricked into revealing their login and password.

Video of Twitter Phishing The BZPharma LOL this is funny Attack

The DM Messages include

Lol. this is me??
lol , this is funny.
Lol. this you??

followed by a link in the form of

____________________________________________________________________

http://example.com/?rid=http://twitter.verify.bzpharma.net/login

Do we need to mention that if you get a message like this, DON’T click on it?

Here ‘example.com’ can vary. As we have seen many variations of the URL in its entirety, you would be wise to avoid clicking on any links which refer to bzpharma.net at the very least.

After the first attack wave, however, the phishers are now using the compromised accounts to send out spam, which resulted in a huge amount of V!agra-related messages on Twitter, which read something similar to this: “Get bigger and have s3x longer. go here”, followed by an address that leads to a s3xual enhancement site.

IT security firm Sophos now has detailed info on the attacks and here is a video describing this Phishing scam:

____________________________________________________________________

Sophos researchers discovered that although the main wave of poisoned messages has been via private direct messages between individual users on Twitter, dangerous links are also being posted in public feeds. This means that innocent users can stumble across the links even if they are not sent it directly, or even if they are not a signed-up user of Twitter.

This phishing attack has been causing headaches for Twitter users all weekend, resulting in thousands of users being put at risk of having their account broken into,” said Graham Cluley, senior technology consultant at Sophos. “It appears what is happening is that the messages are being shared more widely because of third-party services like GroupTweet which extend the standard Twitter direct message (DM) functionality and allow private messages to be sent to multiple users and optionally made public,” continued Cluley. “This has resulted in the bizarre site of Twitter accounts warning their followers about the phishing attack, only to subsequently fall victim to it themselves.

Sophos also reports that the site being used for the Twitter phishing has also been constructed to steal information from users of the Bebo social network. Affected users are advised to change their passwords immediately.

Related Posts Plugin for WordPress, Blogger...

____________________________________________________________________

Tags: , , , , , , , , , , , , , , , , , , ,

Line Break

Author: TechChunks (has written 485 Articles)

TechChunks is a 27-year-old Technology Geek, Web Entrepreneur, SEO Consultant and Social Media Evangelist from Pune (India). Prior to starting this blog, TechChunks has spent many productive years as a Software Engineer, Blogger, Corporate Trainer, Frequent Conference Speaker and Workshop Leader. He has a special interest in "Problem Solving" and can be found hiking on weekends...

17 Responses to " Beware: LOL Phishing Scam Still Circulating on Twitter and Turning into a Spam Wave (Video) "

  1. abhi says:

    The best way is to use http://www.knowurl.com it extracts original URL from shortened URL.

  2. Social comments and analytics for this post…

    This post was mentioned on Twitter by raskenbo: RT @debasispradhan: Video of Twitter Phishing – http://bit.ly/c1oA7H

  3. seo magazine says:

    I too used too got a lot of such this is you messages, I had a pre assumption that those were spam but never thought those were phishing attacks, I clicked on it once but the page never opened because my Chrome gave me a security warning and I do not tend to open sites which shows such warnings
    .-= seo magazine´s last blogpost >> Paypal Indian Banks Withdrawal Issues Resolved!! More Problems Evolved =-.

  4. abhi says:

    Well in that case, no one can help. People need to be careful.

  5. Thanks for suggesting.But I am not affected with phishing.
    .-= Blogging Tips´s last blogpost >> Search Engine Optimization (SEO) – What is it? =-.

  6. These phishers are really dangerous!!! I guess I’ve to be more safe in Twitter now than before…

  7. lol…really dangerous phishers…
    .-= Dev | Technshare´s last blogpost >> 12 ways to promote your blog offline =-.

  8. Rajesh says:

    Phishing is widely used method to hack the accounts.. recently one of friend gone thru some phishing sites for which he has to pay his facebook and orkut accounts..
    .-= Rajesh´s last blogpost >> TechCats Welcomes Guest Bloggers =-.

Leave a Reply

CommentLuv badge

Copyright © 2009-2012 TechChunks – Technology, Gadgets, SEO, Blogging, Social Media. All rights reserved.
Powered by Theme Junkie.
Optimized by Hakukoneoptimointi.