SocialToo has detected a surge in the number of phishing DMs in just the last few hours or so, all with the text, “This you???”, followed by many different variants of URL shorteners that all redirect to a domain ending in kevanshome.org (DO NOT CLICK! YOU WILL BE TAKEN TO A BEBO-LOOKING PAGE ASKING FOR YOUR BEBO CREDENTIALS – DO NOT LOG IN).
This new variant comes after a slew of phishing DMs over the weekend, all with similar text to this one that utilized a URL redirect service, redirecting users to a bzpharma.net URL asking users to log in with their Twitter credentials. While we show little sign that the compromised accounts were fixed by Twitter, we did notice that particular variant seems to have stopped, and we have begun to detect some of those compromised accounts sending out Viagara ads in their stead utilizing the same domain name redirect scheme.
All SocialToo users that have either created at least one DM filter under their Preferences, or signed up for the DM e-mails should be protected from this new variant that just started early this morning. We have blocked over 1,400 DMs so far from this specific variant. We were able to detect this worm from the first DMs sent out (and have measures in place to automatically detect future variants). Users that get DMs in other locations should still be suspicious. While SocialToo deletes the malicious DMs from your account, not all Twitter clients check to see when DMs are deleted. For this reason we recommend you turn on SocialToo DM e-mails and turn off Twitter’s DM notifications. SocialToo users utilizing this service will never get a malicious DM from Twitter that we are able to detect.
SocialToo is not a perfect service – there may still be malicious DMs that get through our filters so we encourage all users to be cautious when receiving DMs with links in them. Look over the domain in the link, verify that you know with absolute certainty that the URL is on twitter.com before providing your credentials. A good rule of thumb is that if a link from a DM takes you to a Twitter login page, you should probably not provide your credentials. Instead, manually type in the Twitter.com URL.
We are constantly finding new ways to protect your DMs from Twitter when you utilize the services we provide at SocialToo. While our service does provide automation tools that increase the number of DMs for some users, these types of attacks often come from your closest friends and family. No one can be trusted in this case, and we ask that you exercise caution amongst all DMs you receive. This protection is intended for all users of SocialToo, whether you choose to automate or not – you just need to follow the instructions above to enable the feature.
As always, follow the @socialtoo account on Twitter for updates on the status of this worm and others. We will also try to keep you updated on this blog as new worms surface.
Half of 
Recently, due to the Twitter Featured Listings on Twitter, several of our users have been approaching up to the millions of followers (Many of the top users on Twitter are using SocialToo! We’re very proud of that), and others in the hundreds of thousands. While we’re very happy for these users, this is a lot of data to process! We think it’s a fun challenge, and are always game for it – we want you to feel confident, that despite the size of your audience, we will be able to continue to provide you top-notch service. Unfortunately, as we work out this challenge some of our larger users, especially those with over 2,000 followers, will see delays in the auto-following we do on their behalf, any catch up services purchased, and numbers in your nightly report e-mails.