New Twitter Phishing Scam
Another day, another phishing or malware scam on Twitter. It seems like these are happening entirely too often, and the reason is that people continue to ignore common sense. Very, very rarely will a site hijack an account of some type without getting input from the account holder. The scam du jour is a Twitter hijack attempt that asks for a username and password, and once received will not only DM your followers with a message, but will also post it publicly on your account. The message will appear as one of the following, or a close variant:
- hah, i think i seen u on here http://videos.dskjkiuw.com/
- this you? http://videos.dskjkiuw.com/
- lol this vid is funny. http://videos.dskjkiuw.com/
- haha check out this vid http://videos.dskjkiuw.com/
DO NOT FOLLOW THESE LINKS AND GIVE YOUR LOGIN INFORMATION!!! This page will take your Twitter login credentials and hijack your account. As of right now it appears to only try to propagate itself by getting others to log in, but it could use your account for other reasons. If you did receive this and you did “log in”, you must CHANGE YOUR PASSWORD IMMEDIATELY!!!
An interesting note about this phishing scam…the graphics are not even up to date. It prompts you to go to a site that looks like the OLD Twitter login page, not the new one. The images are below for comparison.0