Tuesday, September 25, 2012

Twitter users may be victims of direct message malware





A friend of mine recently sent me a direct message on Twitter, it said "lol u didnt se them taping u" and had a link to Facebook. I hadn't remembered being taped in the past few days and I'd never seen my friend use this type of Twitter-shorthand, along with typos. To me, it was obviously spam.




I'm not the only one to be getting these spammy direct messages on Twitter that lead to bogus Facebook links. Apparently a lot of people have been complaining of these messages, according to Sophos analyst Graham Cluley who wrote about it on the Naked Security blog.




Different variations of the direct messages include, "your in this [link] lol" and "lol ur famous now [link]" (I got this one too).




Of course, I didn't click on the link. However, according to Cluley, those people that do click are led to a video player that says, "An update to Youtube player is needed." Users are asked to download what is supposedly called "FlashPlayerV10.1.57.108.exe," but Sophos antivirus products detect it as Troj/Mdrop-EML, which is a backdoor Trojan that can copy itself to accessible drives and network shares.




This is the spam I got via Twitter direct message.




(Credit: Screenshot by Dara Kerr/CNET) A Slate reporter ... [Read more]


No comments:

Post a Comment