Twitter Phishing Attack in Progress – Do Not Click Unknown Links

February 21, 2010 | Comments

If you get a direct message on Twitter looking like this:

Lol. this you?? http://divinelink.net/?rid=http://twitter.verify.bzpharma.net/login

Do not click on the link!

The attack appears to be utilizing the SmartName domain parking service, which allows redirects to third-party sites. The DMs appear in the form of a legit URL, followed by something to the effect of ?rid=http://twitter.verify.bzpharma.net/login in the URL. Those URLs redirect to the latter URL, which is a phished site that looks like the Twitter login page.

  • Unfortunately attacks like this are only going to get more prevelant with the url shortner services out there, harder to tell which links are phishers.
blog comments powered by Disqus