Twitter scam betrays users' lack of savvy

A new scam has successfully duped Twitter users into handing over their cell phone details.

Security firm Sophos is warning that a new scam is spreading virally on Twitter, and that a significant number of people have already fallen for it.

The Online Timer scam claims to measure how long users have spent on the Twitter Website. It spreads via seemingly innocuous Twitter messages along the lines of "I have spent 30 days, 14 hours on Twitter. How much have you? Find out here," followed by a shortened link to a malicious Website.

Anybody who clicks the link is directed to a Website that requests to connect to the user's Twitter account in order to measure their usage. The first thing it actually does, however, is post the same message in the user's feed, this time with a different and seemingly random time measurement, but with the same link.

Oblivious to this happening, the user is rewarded with a pop-up window that claims to show how many views the user's account has had. Again, the number appears to be random. By way of the main payload, a pop-up window then appears offering an IQ test, which it's claimed the user must complete to defeat spam and "verify you are not a bot." Upon completion of the survey, users are requested to enter their cell phone number to receive further questions, although the small print says that users will be sent four text messages a week, at a cost of $2 each.

It's a clever scam that tiptoes effectively through the minefield of credulity. It's not hard to see why people would fall for it, although it's good to see that the savvy and urbane "Twitterites" perhaps aren't that much brighter than the grass-grazing Facebook multitude.

I've always had a quiet admiration for malware writers who manage to succeed. A good attack vector is a piece of pure wit, like a good joke; it manages to bypass our defenses and draw us in. Of course, if the malware is destructively malicious rather than just annoying, then my admiration is a little tempered.

The new Twitter malware follows a scam that works in a similar way, except offering a survey rather than a quiz. Another similar scam claimed to show who was stalking individuals. It's obvious that the same organization is behind each of the attacks.

In many ways, it's surprising it's taken so long for Twitter to be targeted like this. Because of the requirement to stick to 140 characters in each message, most people use URL shortening services. This leaves those clicking the link with absolutely no idea where they're going to end-up (and most of us have learned to have one eye on the status bar whenever we hover over any link).

Twitter is trying to combat this with its service, which claims to be safer. This checks URLs against a list of known malicious sites, and the full URL appears in Tweeted messages. However, is clumsy and confusing to use. To generate a link, you have to precede the original link in your browser bar with for example, and it currently doesn't provide metrics to end users (that is, a measure of how many people have clicked the link). Thus, many people stick with rival services and, the latter being offered by Google. It's possible to wrap or link in a link but then the process of making a quick tweet becomes annoyingly protracted.

Additionally, Twitter relies on users to verify the authenticity of sites that want to "connect" to a user's account. As is becoming clear, users simply aren't scrupulous enough. Many simply don't care. On both Facebook and Twitter, users are encouraged to allow connections from trivial sites and applications as part of day-to-day use.

In short, users are a little too loose with what they link up with, but that helps the wheels of Twitter and Facebook keep rolling.

One would think the notification that a site wants to post on an individual's Twitter feed to be so important that it would be highlighted in red, and might be accompanied by the sound of sirens in case the individual is suddenly struck blind. Alas, that's not the case. The exact phrasing is this: "The application would like the ability to access and update your data on Twitter." It's not even made explicitly clear that the app might post messages.

At the present time it appears the scam no longer works; either the malicious Website is offline, or clicking through to allow permission for connection causes Twitter to explain that the required token is no longer valid.

However, should you find yourself hit with this malware or something similar, the first step is to remove the connection. You can do this by visiting, clicking on your username at the top right, and then clicking the Settings link.

On the page that appears, click the Connections tab and find the app in the list. Then click the Revoke Access button.

You can prune your Twitter feed of the malware messages by going to your list of Tweets (click Home and then the Your Tweets link), and hovering the mouse over the message until a Delete option appears. Run a full virus scan just in case--and while that's completing, it might be a good idea to tweet that you've been infected, but that everything is now cleaned up.

Keir Thomas has been making known his opinion about computing since the last century. His latest Kindle ebooks have just gone on sale . You can learn more about him at . His Twitter feed is @keirthomas .

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags Internet-based applications and servicesspamsecurityvirusestwitterdata protectionsocial mediaphishinginternetFacebooksophos

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Keir Thomas

PC World (US online)
Show Comments

Most Popular Reviews

Latest News Articles


PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?