Skip to main content

Malicious Twitter worm leads users to fake antivirus site

twitterA new worm has invaded Twitter accounts, spreading links to malicious websites that are designed to look an antivirus service. The threat was first reported in a blog post yesterday by Graham Culey of the the Internet security firm Sophos and Kaspersky.

The worm uses Google’s URL-shortener goog.le to post generic links on unsuspecting users’ Twitter accounts. When users click the link, they’re taken to a phony antivirus website promoting a service called “Security Shield.” The program is actually malware seeking to infect computers. When the program is installed it falsely reports a virus infection and asks for money in order to remove the virus from the system.

Fortunately, the threat has been mitigated as most legitimate antivirus programs have been alerting users before any damage is done — provided that virus subscriptions have been recently updated, of course. Google now also appears to be aware of the problem and has disabled goog.le links that redirect to the malicious site. Users who discovered mysterious links posted to their feeds should change their Twitter passwords.

It’s not the first time Twitter has fallen under attack from a worm. In September, the micro-blogging site’s security was breached and thousands of users found their accounts hijacked to post links to porn sites.

Editors' Recommendations

Aemon Malone
Former Digital Trends Contributor
More Twitter users will soon see fact-check notes on tweets
The Twitter app on the Sony XPeria 5 II.

Birdwatch, Twitter's community fact-checking pilot program, is expanding and getting a few updates. And for users in the U.S. that means more of them will be seeing a few tweets in their timelines that feature notes which add context to the tweets themselves.

On Wednesday, the official Twitter account for the bird app's Birdwatch program posted a series of tweets announcing its expansion.

Read more
Apple’s antivirus strategy for Mac has gone fully preemptive, but is that enough?
Security and Privacy settings open on a MacBook.

Apple made its Macs even better at fighting malware in recent years, but don't relax just yet.

A recent blog post by Howard Oakley at the Eclectic Light Company details the changes Apple has quietly made in the past six months that mark a distinct change in strategy for protecting Macs, including spots where there are still holes of vulnerability, specifically for some older Macs.

Read more
Breaking down the Twitter whistleblower allegations and how it affects the Musk takeover
Jack Dorsey sits in front of a Twitter logo.

On Tuesday, The Washington Post published an extensive report about a Twitter whistleblower who alleges that the social media company's executives have misled, well, just about everyone (but especially federal regulators and Twitter's own board of directors), about its own security issues. The whistleblower complaint details quite a few alleged serious problems at Twitter, including security issues and a lack of resources to fully address disinformation. Notably, the complaint also mentions Twitter's spam and bot issues. If you've been following along with the Elon Musk Twitter takeover saga, you know that ascertaining the true number of bots on the bird app has been a particular roadblock for Twitter's acquisition.

In July, the complaint was filed with two agencies (the Securities and Exchange Commission (SEC) and the Federal Trade Commission (FTC), as well as the Department of Justice. And the complaint wasn't filed by just anybody. The whistleblower was none other than Twitter's former head of security, Peiter Zatko. Zatko is also a well-respected hacker himself, also known as "Mudge."

Read more