Skip to main content

New phishing campaign targets Twitter Blue users amid X rebrand confusion

Web Hosting & Remote IT Support

A new phishing campaign is targeting Twitter Blue subscribers amid the social media platform’s messy transition to X, and the consequences could be catastrophic.

Twitter owner Elon Musk and new CEO Linda Yaccarino hope that the platform will soon become X, but the transition has been anything but smooth, with rebranding at the HQ going, well, not to plan. Furthermore, the discrepancy between the website and mobile apps is giving some users a complete headache.

Hoping to capitalize on this confusion, one threat actor is offering Twitter Blue subscribers to transfer their membership to X, but all this does is give the cybercriminal access to a user’s entire Twitter account.

Twitter Blue/X phishing emails

To an unsuspecting target, the email looks to come from a legitimate source, with the display name showing ‘sales@x.com.’ The email passes SPF authentication checks despite actually coming from mailing list platform Sendinblue (now known as Brevo). 

A screenshot of the email posted by Twitter user @fluffypony claims that a victim’s “existing subscription is nearing its expiration and requires migration,” with a link directing users to a completely legitimate API authorization page. The fact that it’s legitimate means that, upon approval, the threat actor then has access to a user’s Twitter account.

Along with a few view-only capabilities, the API allows the threat actor to amend follwers, update profile and account settings, post and delete Tweets, engage with other Tweets, and more.

Fortunately, revoking API access is fairly easy on Twitter, by navigating to Settings > Security and account access > Apps and sessions > Connected apps.

Checking these settings is generally a good idea whether you have been targeted by this phishing attack or not, purely in the interest of good Internet hygiene. For those not quick enough to disable the dodgy service, it’s unclear what the result could be. In the worst-case scenario, they could be locked out of their account with any manner of activity going on, in which case they may want to consider using identity theft protection software.



via Hosting & Support

Comments

Popular posts from this blog

How to watch Vigil season 3 online from anywhere – it's *FREE*

Web Hosting & Remote IT Support Watch Vigil season 3 for free on BBC iPlayer (UK) Use NordVPN to watch BBC iPlayer when abroad The first two of the six episodes arrive on Sunday, August 30 After uncovering the dark secrets of drone warfare technology in the Middle East in season 2, Vigil season 3 will see DCI Amy Silva (played by Suranne Jones) and DS Kirsten Longacre (played by Game of Thrones star Rose Leslie) come together to investigate the murder of a covert British Special Forces operative at a remote Arctic search station in a Russian enclave. From high-speed car chases and explosions to tense, gun-packed standoffs, the season 3 trailer tells us that the new season is going to be bigger, more intense, and higher-stakes than anything the duo has handled before. Plus, creator and writer Tom Edge has already hinted that Amy and Kirsten will be looking to avoid an international confr...

Windows 10 update is causing lots of problems – including nasty crashes

Web Hosting & Remote IT Support Windows 10 users are suffering at the hands of some fresh bugs introduced by the latest update for the OS from Microsoft. That would be KB5026361, the cumulative update for Windows 10 for May, which was released a couple of weeks back, and appears to be causing a bunch of glitches and more serious problems. In the serious category we can file some Reddit users who are complaining on two counts of the patch ‘bricking’ their PC, and also reports of Blue Screen of Death (BSoD) crashes post-update. Some of those BSoDs offer up an error that reads ‘Process1 Initialization Failed’ and as Neowin , which spotted this, explains, this seemingly occurs due to the Bootcat.cache file becoming corrupted (or its size having changed since the last time the PC booted). Other Windows 10 users are encountering a problem that’ll sound familiar, no doubt – the failure to install the update, often accompanied with a meaningless error code (such as ‘0x800f0922’ whi...