{"id":17774,"date":"2020-02-19T10:10:02","date_gmt":"2020-02-19T18:10:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/02\/19\/news-11507\/"},"modified":"2020-02-19T10:10:02","modified_gmt":"2020-02-19T18:10:02","slug":"news-11507","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/19\/news-11507\/","title":{"rendered":"Rudy Giuliani&#8217;s Twitter mishaps invite typosquatters and scammers"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Wed, 19 Feb 2020 17:21:08 +0000<\/strong><\/p>\n<p>Former cybersecurity czar Rudy Giuliani has been targeted by typosquatters on Twitter, thanks to copious misspellings and other keyboarding errors made in a number of his public tweets. In a tweet sent out on Sunday, Giuliani meant to send his 650,000-plus followers to his new website, RudyGiulianics.com. Instead, a space added after &#8220;Rudy&#8221; sent users on a redirection quest that ultimately landed on a <a href=\"https:\/\/www.cnet.com\/news\/why-rudy-giulianis-twitter-typos-are-a-security-fail\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"web page laced with adware (opens in a new tab)\">web page laced with adware<\/a>. <\/p>\n<p><a rel=\"noreferrer noopener\" aria-label=\"Typosquatting (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2016\/06\/explained-typosquatting\/\" target=\"_blank\">Typosquatting<\/a> has long been used as a way to capitalize on mistakes made by those with clumsy fingers. A mistyped URL, which would normally lead users to a 404 error page, is instead redirected to a completely unrelated site\u2014often one designed for ill intent. For example, let&#8217;s say you enter yotube.com into your browser&#8217;s address bar instead of youtube.com. Rather than seeing the normal YouTube portal, you will instead be redirected via a few ad networks and most likely end up to a scam page, thanks to the handy work of enterprising typosquatters.<\/p>\n<p>Typosquatting can be a profitable business, as threat actors will register domains lexically close to big brand names or popular websites for heavy traffic gains. The end goal isn&#8217;t always to monetize via <a rel=\"noreferrer noopener\" aria-label=\"malvertising (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/101\/2016\/06\/truth-in-malvertising-how-to-beat-bad-ads\/\" target=\"_blank\">malvertising<\/a> redirections\u2014it could be phishing, data theft, or even hacktivism.<\/p>\n<p>In Giuliani&#8217;s case, a public political figure has been identified by cybercriminals for his tendency toward typo-laden tweets. In fact, Giuliani&#8217;s <a rel=\"noreferrer noopener\" aria-label=\"Twitter account (opens in a new tab)\" href=\"https:\/\/twitter.com\/rudygiuliani\" target=\"_blank\">Twitter account<\/a> contains numerous tweets with misspellings around his personal website that sometimes lead to trolling attempts or redirect to malvertising schemes. We examine a few of these instances.<\/p>\n<h3>Typo leads to political trolling<\/h3>\n<p>Here&#8217;s a <a rel=\"noreferrer noopener\" aria-label=\"tweet (opens in a new tab)\" href=\"https:\/\/twitter.com\/RudyGiuliani\/status\/1228910572302934016?s=20\" target=\"_blank\">tweet<\/a> sent from Giuliani&#8217;s account using an iPad. Whoever  composed that tweet forgot to add a space between the word &#8220;Watch&#8221; and &#8220;rudygiulianics.com&#8221;.<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"42434\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/tweet1_\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_.png\" data-orig-size=\"599,562\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"tweet1_\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_-300x281.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_.png\" alt=\"\" class=\"wp-image-42434\" width=\"444\" height=\"416\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_.png 599w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet1_-300x281.png 300w\" sizes=\"auto, (max-width: 444px) 100vw, 444px\" \/><\/figure>\n<p>As a result, the website becomes Watchrudygiulianics.com which was registered a day after the tweet:<\/p>\n<pre class=\"wp-block-preformatted\">Domain Name: watchrudygiulianics.com Registrar: GoDaddy.com, LLC Creation Date: 2020-02-16T05:23:50Z<\/pre>\n<p><a rel=\"noreferrer noopener\" aria-label=\"Visiting the site (opens in a new tab)\" href=\"https:\/\/urlscan.io\/result\/9f6756c5-bf0c-4d46-938e-8ab1218dbdb5\/\" target=\"_blank\">Visiting the site<\/a> immediately redirects users to https:\/\/www.drugrehab.com\/treatment\/, a site for help with substance abuse.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42428\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/redir1-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1.png\" data-orig-size=\"733,827\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"redir1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1-266x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1-532x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1-532x600.png\" alt=\"\" class=\"wp-image-42428\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1-532x600.png 532w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1-266x300.png 266w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir1.png 733w\" sizes=\"(max-width: 532px) 100vw, 532px\" \/><\/figure>\n<p>In another <a href=\"https:\/\/twitter.com\/RudyGiuliani\/status\/1229041728541380609?s=20\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"example (opens in a new tab)\">example<\/a>, we see a much more subtle typo for Giuliani&#8217;s website, where a single &#8216;i&#8217; is missing in RUDYGIULIANCS.com (the correct site is rudygiulianics.com).<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42426\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/tweet2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2.png\" data-orig-size=\"600,762\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"tweet2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2-236x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2-472x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2-472x600.png\" alt=\"\" class=\"wp-image-42426\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2-472x600.png 472w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2-236x300.png 236w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet2.png 600w\" sizes=\"(max-width: 472px) 100vw, 472px\" \/><\/figure>\n<p>The domain rudygiuliancs.com was also registered recently (but before the tweet came out, so it either was preemptive registration for a forthcoming typo or perhaps the typo had been made already).<\/p>\n<pre class=\"wp-block-preformatted\">Domain Name: rudygiuliancs.com Registrar: Wild West Domains, LLC Creation Date: 2020-02-07T16:30:38Z<\/pre>\n<p>This time, <a rel=\"noreferrer noopener\" aria-label=\"visiting this link (opens in a new tab)\" href=\"https:\/\/urlscan.io\/result\/8c7fe1f0-258d-4e9c-951b-e256e414627f\/\" target=\"_blank\">visiting this link<\/a> redirects visitors to a <a rel=\"noreferrer noopener\" aria-label=\"Wikipedia page (opens in a new tab)\" href=\"https:\/\/en.wikipedia.org\/wiki\/Trump%E2%80%93Ukraine_scandal\" target=\"_blank\">Wikipedia page<\/a> for the Trump-Ukraine scandal:<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42429\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/redir2-3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2.png\" data-orig-size=\"741,828\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"redir2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2-268x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2-537x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2-537x600.png\" alt=\"\" class=\"wp-image-42429\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2-537x600.png 537w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2-268x300.png 268w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/redir2.png 741w\" sizes=\"(max-width: 537px) 100vw, 537px\" \/><\/figure>\n<h3>Malvertising and other traffic schemes<\/h3>\n<p>As mentioned earlier, typosquatters will typically watch popular domain names and register new ones that are likely going to be a result of a typo. Because Giuliani has over 650,000 followers on Twitter and is a well-known political figure regularly in the headlines, scammers know he&#8217;s a good source of potential web traffic purely from typosquatting.<\/p>\n<p>In Sunday&#8217;s example, a typo led to a malvertising scheme. This <a rel=\"noreferrer noopener\" aria-label=\"time (opens in a new tab)\" href=\"https:\/\/twitter.com\/RudyGiuliani\/status\/1228960604649611264?s=20\" target=\"_blank\">time<\/a>, a space was inserted between &#8220;Rudy&#8221; and &#8220;Giulianics.com&#8221;.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42430\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/tweet3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3.png\" data-orig-size=\"596,717\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"tweet3\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3-249x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3-499x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3-499x600.png\" alt=\"\" class=\"wp-image-42430\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3-499x600.png 499w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3-249x300.png 249w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/tweet3.png 596w\" sizes=\"(max-width: 499px) 100vw, 499px\" \/><\/figure>\n<p>This typo resulted in a link to Giulianics.com, a domain registered at the end of January.<\/p>\n<pre class=\"wp-block-preformatted\">Domain Name: giulianics.com Registrar: GoDaddy.com, LLC Creation Date: 2020-01-31T20:29:50Z<\/pre>\n<p>As seen in the image above, a series of redirects will happen once you visit that domain. This is typical for malvertising chains that fingerprint your browser and other settings in order to deliver the appropriate payload.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" data-attachment-id=\"42433\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/traffic-30\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic.png\" data-orig-size=\"967,471\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"traffic\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic-300x146.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic-600x292.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic.png\" alt=\"\" class=\"wp-image-42433\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic.png 967w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic-300x146.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/traffic-600x292.png 600w\" sizes=\"(max-width: 967px) 100vw, 967px\" \/><\/figure>\n<p>In this instance, visiting from the United States via Google Chrome, we were served a browser extension called Private Browsing:<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42431\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/extension-8\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension.png\" data-orig-size=\"1053,565\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"extension\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension-300x161.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension-600x322.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension-600x322.png\" alt=\"\" class=\"wp-image-42431\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension-600x322.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension-300x161.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extension.png 1053w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Although we did not examine the extension in detail, <a rel=\"noreferrer noopener\" aria-label=\"several comments (opens in a new tab)\" href=\"https:\/\/chrome.google.com\/webstore\/detail\/private-browsing-by-safel\/fpckohnjiaonmklkjnlplokplhhijalm\/related\" target=\"_blank\">several comments<\/a> from the Google Play Store say the extension was forced while browsing the web.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"42432\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/attachment\/extensiondetails\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails.png\" data-orig-size=\"914,675\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"extensiondetails\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails-300x222.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails-600x443.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails-600x443.png\" alt=\"\" class=\"wp-image-42432\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails-600x443.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails-300x222.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/extensiondetails.png 914w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Among other capabilities, it can read your browser history, the data you enter on sites, and can change your default search engine. As a rule of thumb, it is generally recommended to refrain from installing too many browser extensions, especially when they are promoted via unwanted redirects.<\/p>\n<p>In late January, there was a <a rel=\"noreferrer noopener\" aria-label=\"report (opens in a new tab)\" href=\"https:\/\/twitter.com\/nahmias\/status\/1222231315023527937?s=20\" target=\"_blank\">report<\/a> that visiting Giuliani&#8217;s website distributed malware. We weren&#8217;t able to confirm it at that time, but in light of the current typo situation, we believe it&#8217;s more likely that one of the tweets containing the wrong link led to a malvertising chain, and possibly to a browser locker.<\/p>\n<h3>Monitoring popular accounts for mistakes<\/h3>\n<p>Many attacks we see in the wild are opportunistic, praying on the latest news or events likely to draw attention. There&#8217;s also always been great interest in popular social media accounts, but typically by hacking them directly. In this case, opportunistic actors are waiting for the next typo to happen in order to push out their own message or to monetize on it via malicious redirects.<\/p>\n<p>This serves as a reminder that even well-known or verified social media accounts can send users in unintended directions leading to scams or malware. In a sense, any kind of communication can be abused for an attacker&#8217;s own gain by recognizing a pattern of predictable mistakes and immediately acting upon them.<\/p>\n<p>For those wanting protection against such redirections and other malicious website activity, Malwarebytes offers a <a rel=\"noreferrer noopener\" aria-label=\"free browser extension (opens in a new tab)\" href=\"https:\/\/www.malwarebytes.com\/browserguard\/\" target=\"_blank\">free browser extension<\/a> that takes an aggressive stance on blocking malvertising and other dubious schemes.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/\">Rudy Giuliani&#8217;s Twitter mishaps invite typosquatters and scammers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Wed, 19 Feb 2020 17:21:08 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/' title='Rudy Giuliani's Twitter mishaps invite typosquatters and scammers'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/02\/shutterstock_712241932.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Rudy Giuliani&#8217;s Twitter account contains many typos that lead to the wrong website\u2014and scammers and typosquatters are taking advantage.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/scams\/\" rel=\"category tag\">Scams<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/adware\/\" rel=\"tag\">adware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/browser-extensions\/\" rel=\"tag\">browser extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/cybersecurity-czar\/\" rel=\"tag\">cybersecurity czar<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/giuliani\/\" rel=\"tag\">giuliani<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/hacktivism\/\" rel=\"tag\">hacktivism<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malvertising\/\" rel=\"tag\">malvertising<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malvertising-schemes\/\" rel=\"tag\">malvertising schemes<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/political-targets\/\" rel=\"tag\">political targets<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/rudy-giuliani\/\" rel=\"tag\">rudy giuliani<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scams\/\" rel=\"tag\">scams<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tweets\/\" rel=\"tag\">tweets<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/twitter\/\" rel=\"tag\">twitter<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/typo\/\" rel=\"tag\">typo<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/typosquatting\/\" rel=\"tag\">typosquatting<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/' title='Rudy Giuliani's Twitter mishaps invite typosquatters and scammers'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/02\/rudy-giulianis-twitter-mishaps-invite-typosquatters-and-scammers\/\">Rudy Giuliani&#8217;s Twitter mishaps invite typosquatters and scammers<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10468,19414,24256,24257,17526,10531,24258,24259,24260,10574,19541,454,24261,15550],"class_list":["post-17774","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-adware","tag-browser-extensions","tag-cybersecurity-czar","tag-giuliani","tag-hacktivism","tag-malvertising","tag-malvertising-schemes","tag-political-targets","tag-rudy-giuliani","tag-scams","tag-tweets","tag-twitter","tag-typo","tag-typosquatting"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17774"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17774\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17774"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}