Online survey scam spreading on Twitter

The survey, which appears harmless enough, centres on how long users have been online to the social networking and microblogging site, noting: "I have spent 379 days, 9096 hours on Twitter. How much have you? Find out here: [LINK]"

According to IT security vendor Sophos, the messages, posted by an application called "Your Online Timer", include a link which - if clicked on by other Twitter users - encourages them to authorise "Your Online Timer" to access and update their Twitter accounts.

If the application is approved, however, users will be taken to a website which claims it will find out the time spent to date on Twitter - and the page pops up a survey which earns the scammers money for each questionnaire completed.

Graham Cluley, a senior technology consultant with Sophos, says that, in addition, without explicit approval, the Twitter account of the victim is updated with a status update - spreading the link virally to other Twitter users.

"Viral scams like this are commonly encountered on Facebook, but are now being spread by their creators onto Twitter too. It's possible that the people behind these attacks view Twitter users as a softer target, who might generate them more income", he said in his security blog.

"Social networks have a responsibility to protect their users from scams and spam - but ultimately it's down to the user to think very carefully before handing over the keys to their social network account to a complete unknown application", he explained.

Cluley went on to say that affected users should revoke the application's access to their Twitter account immediately.

This can be done, he adds, by entering Settings/Connections and revoking the rights to the relevant application.

"If the application's access to your account is not revoked, the scammers could use it to spread other messages - potentially including links to malicious websites, phishing or other spam campaigns", Cluley advised.

"The last thing you want is for your Twitter followers to believe that you are being sloppy over your account's security, and potentially putting them at risk too", he noted.

 

 

What’s hot on Infosecurity Magazine?