ng-nz logo
Story image

Twitter users beware: Phishers target account verification in latest attacks

01 Feb 2017

Twitter is now the target of a phishing attack that uses methods to trick brand managers and social influencers into fake account verification.

Security firm Proofpoint discovered the phishing attack, which places ads on websites and lures brand managers to false verification pages.

The ads come from an account that copies the official Twitter support account. It looks genuine through Twitter branding, logos and colours. However, the handle @SupportForAll6 and the low number of followers detracts from the authenticity.

The scam uses Twitter-sponsored ads, which appear in feeds without any user interaction, need to follow or messaging requirements.

When users click the link, they are taken to a domain called twitterhelp.info. Proofpoint says the domain should give the game away, but otherwise the site looks genuine.  The URL resolves to an IP address that has previously been used for phishing activities. When users follow instructions, they are asked for Twitter usernames, emails, phone numbers and the account passwords.

Users are then prompted for their credit card number and security code for additional ‘verification’.  The form includes a template for extracting payment information from Github and tells users ‘they will not be charged’.

“While there is no validation on the form asking for account information, allowing users to submit empty values, this is not the case with the financial information; this cannot be submitted without providing the requested credit card information,” Proofpoint says.

The final step of the process includes a thank you note and notification to receive an email with verification details. The site then redirects to the genuine Twitter page, concluding the apparent legitimacy of the transaction.

Proofpoint says that the phishing attempts are not overly sophisticated, use social engineering, traditional phishing methods and social impersonation to come up with new ways of creating attacks.

What’s worse is that these techniques could be applied to any social media platform that uses account verification.

Devin Redmond, vice president and general manager of Digital Security and Compliance, Proofpoint, says attackers will always go where their victims are. "Social media provides them with a unique opportunity to directly reach large audiences, without fighting corporate networks and their often-fortified security defences. Our research conclusively shows this trend is only picking up speed. In the first six months of 2016, we saw a 150% increase in social media phishing attacks when compared to the same period the prior year. And that volume increased by 300% Q3 vs. Q2 2016,” he says.

Twitter’s Brand Verification and account verification have been described as ‘powerful’ ways for brands to distance themselves from fake, parody and fraudulent accounts. When a brand is authenticated, it receives a special badge that shows users the account is verified.

“Our latest discovery, that cybercriminals are actively looking to tempt users into verified account phishing scams, underscores our assertion that social media security and visibility should be on every Australian organization’s radar. Phishing will be a serious threat to Australian employees, data and companies throughout 2017. We anticipate that cybercriminals will continue to target Australians across the channels they use to work today, which includes email, social media networks and mobile devices,” Redmond says.

Story image
Kiwi scoops grand photography prize at Sony Alpha Awards
Wanaka-based Oscar Hetherington won this year’s award for his seascape photo, called ‘Back Wash’. He’s the fourth consecutive Kiwi to win the grand prize – and $10,000 worth of Sony camera gear to boot.More
Story image
Kiwi game developers move forward with indigenous gaming platform Katuku Island
“We created Katuku Island to bring cultural literacy to a technological platform that uses Maori Toi graphics, sounds, characters, tribal tattoo and indigenous challenges. As an indigenous researcher and business owner, I wanted to make a difference.”More
Story image
The Outer Worlds (Switch): A great game but a terrible port 
Anyone that was excited about this Switch port was waiting to see how the graphics will turn out. We were right to be worried, as this is the side that really pulls this game down.More
Story image
HP Inc pledges to eliminate 75% of single-use plastic by 2025
This transition from plastic to molded fibre has already eliminated 933 tonnes of hard-to-recycle expanded plastic foam last year, according to HP.More
Story image
Hands-on review: JBL Tune 220TWS
Another great part of the design is the earbuds themselves. Most other earbuds on the market can’t be worn for more than two hours at a time because of the amount of pressure they put on ear canals. Thankfully, the JBL Tune 220 were designed with all-day wear in mind. More
Story image
Almost 40% of the Earth's population will be gamers by 2023
There will be 3 billion gamers on the planet by the time 2023 comes along, and the gaming market will suprass US$200 billion worldwide during the same year, according to the latest data from Newzoo.More