⚡️WARNING ⚡️: Do NOT install the "My Twitter Family Tree" app. U have to grant excessive permissions & right now it appears to be sending out automated tweets to suck more people in. Anything that shows the "Created with ...." at the bottom of the tweet was likely auto-generated
Here are the permissions you are granting this app ... https://twitter.com/candyvonchulip/status/1379710514285182977
This has all the hallmarks of the malicious @Twitter app "Confirm Your Age" @realShawnEib and myself reported on back in 2018 .. with an added twist. #malapps #infosec #cybersecurity @TwitterSafety https://www.slickrockweb.com/malicious-twitter-applications.php
These actors have gained access to 1000's of Twitter accounts and I am not sure the people thinking this is a fun little online game understand what kind of access they are giving up. It appears to be ongoing. #infosec
Hmmmm ... a bitcoin account? Yeah ... probably not random.
If u look at this tweet which is the same one at the start of this thread a few days ago, u will notice that Twitter is attempting 2 take this down. "erased20554781" means they have suspended that 3rd party API token. Problem is this group is regenerating more unique client names
You can follow @SlickRockWeb.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: