The phishing messages look like this:
[aditude-amp id="flyingcarpet" targeting='{"env":"staging","page_type":"article","post_id":162225,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"business,social,","session":"D"}']“Lol. this you?? http://divinelink.net/?rid=http://twitter.verify.bzpharma.net/login”
Warnings of the attack began circulating on Twitter in the U.S. on Saturday afternoon. “The attack appears to be utilizing the SmartName domain parking service, which allows redirects to third-party sites,” said Jesse Stay, founder of the SocialToo Twitter enhancement service. “The DMs appear in the form of a legit URL, followed by something to the effect of ?rid=http://twitter.verify.bzpharma.net/login in the URL. Those URLs redirect to the latter URL, which is a phished site that looks like the Twitter login page.”
Stay was happy to point out that SocialToo’s automatic spam filtering for Twitter direct messages blocks the attack automatically for his customers. As of 6 pm MountaIn time in Stay’s native Salt Lake City, he said SocialToo had blocked more than 600 of the messages. “To enable the Phishing protection on SocialToo,” he wrote, “users have to either enable the DM E-mails in their preferences (these replace Twitter’s DM E-mails and will be a premium feature in the future), or create at least one DM Filter in their preferences.”
AI Weekly
The must-read newsletter for AI and Big Data industry written by Khari Johnson, Kyle Wiggers, and Seth Colaner.
Included with VentureBeat Insider and VentureBeat VIP memberships.
“These numbers are still going up as we speak,” Stay added, “so Twitter has still not put an end to the problem.”
VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Learn More