::Trend Micro Threat Resource Center::

25 September 2009

Twitter warns of direct-messaging worm

Social-networking service Twitter warned users on Wednesday that a link sent by direct message redirects users to a malicious site that attempts to steal their account credentials.

It's unclear how many users of the microblogging service had fallen prey to the phishing scheme, which sends victims to a replica of the Twitter logon page. Accounts compromised by the attack will send out messages, which resembles "rofl this you on here? http:// videos.twitter.*****-logins01.com," to their followers, according to reports.

"A bit o'phishing going on -- if you get a weird direct message, don't click on it and certainly don't give your login creds!" Twitter warned users through its spam channel.

Source