Twitter pushed out a password reset Tuesday evening to accounts that were following suspicious users. The move comes in the wake of a revelation that phishers were attempting to steal usernames and passwords using fake BitTorrent sites.
Twitter foiled the plan as part of its ongoing monitoring for odd activity. Twitter noticed a sudden surge in followers for a couple of accounts in the last five days. When Twitter technicians started digging, they discovered a plot that compelled immediate action.
“Torrent sites aren’t exactly new; however, this is one of the first times that we’ve seen an attack that came from this vector,” said Del Harvey, director of trust and safety at Twitter. “It appears that for a number of years, a person has been creating torrent sites that require a login and password as well as creating forums set up for torrent site usage and then selling these purportedly well-crafted sites and forums to other people innocently looking to start a download site of their very own.”
A Patient Cybercriminal
But Harvey said these sites came with a nefarious bonus, of sorts, in the form of security exploits and backdoors throughout the system. This patient cybercriminal pushed out the torrents, waited for the forums and sites to get popular, and then used those exploits to get access to the username, e-mail address, and password of every person who signed up.
“Additional exploits to gain admin root on forums that weren’t created by this person also appear to have been utilized,” Harvey said. “In some instances, the exploit involved redirecting attempts to access the forums to another site that would request log-in information. This information was then used to attempt to gain access to third-party sites like Twitter.”
Twitter has yet to identify all the forums involved. In fact, Harvey admitted, it’s not…