Twitter Worm Pushing Rogue Antivirus Scam

Twitter Worm Pushing Rogue Antivirus Scam

Written By
Brian Prince
Brian Prince
Jan 20, 2011
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Thousands of Twitter users are believed to have been hit with malicious links tied to a rogue antivirus scam circulating the microblog service.

The scam is spreading through malicious links abusing the goo.gl URL shortening service. According to Kaspersky Lab, the malicious links redirect users to different domains with an “m28sx.html” page. That HTML page redirects users to a static domain with a Ukrainian top-level domain. From there, blogged Kaspersky Lab Senior Malware Researcher Nicolas Brulez, the domain redirects the user to an IP address pushing fake antivirus.

“Once you are on this website,” Brulez blogged, “you will get [a] warning that your machine is running suspicious applications and you are encouraged to scan it. … The user is invited to remove all the threats from their computer, and will download a fake Anti Virus [sic] application called ‘Security Shield.'”

Del Harvey, director of Trust and Safety for Twitter, tweeted during the day that the company was working to remove the malicious links and reset passwords on compromised accounts.

“What isn’t yet clear is how the Twitter users found their accounts compromised in this way,” blogged Graham Cluley, senior technology consultant at Sophos. “The natural suspicion would be that their usernames and passwords have been stolen. It certainly would be a sensible precaution for users who have found their Twitter accounts unexpectedly posting goo.gl links to change their passwords immediately.”

These kinds of attacks are hardly new to Twitter. In December, users were targeted with shortened links that redirected them to the compromised site of a French furniture company before passing them on to other domains. In that case, the malicious URLs pointed to a copy of the Neosploit attack toolkit.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.