Hackers exploiting DM to Hijack Twitter and WhatsApp accounts
With the Twitter accounts of Megastar Amitabh Bachchan and singer Adnan Sami getting hacked, security researchers have warned that users ought to deliberate before clicking on the links received within the Twitter Direct Message (DMs).
Singer Adnan Sami's Twitter account was allegedly hacked on Tuesday by Ayyildiz Tim, the same Turkish hacker cluster that attacked star Amitabh Bachchan's microblogging page a day ago. Just like Bachchan's profile was compromised, the cluster replaced Sami's profile picture with a photograph of Pakistan PM Imran Khan and altered the bio, adding "Ayyildiz Tim Love Pakistan" with an emoji of Pakistani and Turkish flags.
"Their Modus operandi looks like they are sending DM to the victims Twitter account and if the victim opens the DM he/she is directed to a phishing page which looks like a genuine page," Sanjay Katkar, Joint Managing Director and Chief Technology officer, Quick Heal Technologies Ltd.
"If the user fills the login credentials on this page his login information is gone to the hackers who later use it to login and change the original password and take control of the account," he said, adding that there are alternative ways that a twitter account will compromise.
The French security researcher who uses the pseudonym Elliot Alderson pointed to a user who goes by the name Kerem Sah Noyan on Twitter and uses the handle @NoyanAyt2002 as the person behind the hack.
Bachchan's page was restored within half-an-hour after the Mumbai Police alerted the cyber unit. The group had antecedently hacked Twitter accounts of actors Shahid Kapoor and Anupam Kher among others as well.
"This is an important call to the whole world! We do condemn the irrespective behaviors of Iceland republic towards Turkish footballers. We speak softly but carry a big stick and inform you about the Big Cyber Attack here. As Ayyildiz Tim Turkish Cyber Army," read the first tweet after the attack on Monday.