Gets distributed via Direct Messages

Nov 13, 2009 15:12 GMT  ·  By

Security researchers warn of a shady IQ test being promoted on Twitter via the Direct Messages feature. This is actually a scam that tries to trick people into subscribing to a useless mobile service for $9.99 per month.

According to threat analysts from Trend Micro, this latest spam campaign is being instrumented from compromised Twitter accounts. "The accounts are used to send out Direct Messages to the followers of the users who own the compromised accounts," the researchers note.

These private messages try to convince users into taking an IQ test by visiting the included link. Once on the dubious page, the user indeed has the ability to take such a test, however, there's a catch. At the end, they are asked for their mobile phone number, allegedly in order to receive the results.

"Though the real motive for this scheme is unclear, we believe that this was set up to gather mobile numbers from unknowing users to become potential targets for SMS spam or other mobile-related attack," JM Hipolito, technical communications specialist at Trend, writes. Things are actually pretty clear if you read the fine print on the website, which makes it clear that "This is an auto renewing subscription service that will continue until canceled […]" and that it is "Available for $9.909 per month charged on your wireless account or deducted from your prepaid balance for 3 alerts per week."

This lead gen scam has been intensively used in Facebook games and other websites, until being banned recently. According to TechCrunch, which at the beginning of this month exposed an entire ecosystem of similar schemes plaguing Facebook and MySpace users, the company behind this particular one is called Tattoo Media.

The Consumer Complaints Board website has several entries dedicated to the IQ Quiz deception going back to October 2008. The fact that this scam has now hit Twitter and is being distributed through compromised accounts makes it clear that its creators are not ready to bury it and are willing to partner with anyone in order to reach their goals, even cyber criminals.

Photo Gallery (2 Images)

IQ Quiz scam moves from Facebook to Twitter
Screenshot of IQ Quiz scam website
Open gallery