Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

New phishing campaign targets Twitter Blue users amid X rebrand confusion

  • July 29, 2023
Total
0
Shares
0
0
0


A new phishing campaign is targeting Twitter Blue subscribers amid the social media platform’s messy transition to X, and the consequences could be catastrophic.

Twitter owner Elon Musk and new CEO Linda Yaccarino hope that the platform will soon become X, but the transition has been anything but smooth, with rebranding at the HQ going, well, not to plan. Furthermore, the discrepancy between the website and mobile apps is giving some users a complete headache.

Hoping to capitalize on this confusion, one threat actor is offering Twitter Blue subscribers to transfer their membership to X, but all this does is give the cybercriminal access to a user’s entire Twitter account.

Twitter Blue/X phishing emails

To an unsuspecting target, the email looks to come from a legitimate source, with the display name showing ‘[email protected].’ The email passes SPF authentication checks despite actually coming from mailing list platform Sendinblue (now known as Brevo). 

A screenshot of the email posted by Twitter user @fluffypony claims that a victim’s “existing subscription is nearing its expiration and requires migration,” with a link directing users to a completely legitimate API authorization page. The fact that it’s legitimate means that, upon approval, the threat actor then has access to a user’s Twitter account.

Along with a few view-only capabilities, the API allows the threat actor to amend follwers, update profile and account settings, post and delete Tweets, engage with other Tweets, and more.

Fortunately, revoking API access is fairly easy on Twitter, by navigating to Settings > Security and account access > Apps and sessions > Connected apps.

Checking these settings is generally a good idea whether you have been targeted by this phishing attack or not, purely in the interest of good Internet hygiene. For those not quick enough to disable the dodgy service, it’s unclear what the result could be. In the worst-case scenario, they could be locked out of their account with any manner of activity going on, in which case they may want to consider using identity theft protection software.




Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Google Bard content should be fact-checked, recommends current Google VP

  • July 29, 2023
View Post
Next Article
  • News

The week’s biggest tech news: from Samsung Unpacked to DJI’s new drone and more

  • July 29, 2023
View Post
You May Also Like
View Post
  • News

Many firms are struggling to keep up with their cloud and security work

  • October 2, 2023
View Post
  • News

Microsoft says it won’t let users remove this divisive Windows 11 app

  • October 2, 2023
View Post
  • News

Diablo 4 world bosses will be less of a headache in Season 2

  • October 2, 2023
View Post
  • News

Agent 64: Spies Never Die trailer confirms GoldenEye’s best feature – split-screen multiplayer

  • October 2, 2023
View Post
  • News

Encrypted email Skiff unveils new tool to silence annoying senders

  • October 2, 2023
View Post
  • News

Say goodbye, Marvel’s Avengers has officially been delisted across all platforms

  • October 2, 2023
View Post
  • News

The Umbrella Academy season 4 arrives in 2024 – and fans are already hunting for story clues

  • October 2, 2023
View Post
  • News

Businesses are spending thousands on unnecessary software every day

  • October 2, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.