Found an interesting spam/scam scheme today:
- Attacker posts their link that redirects to a legit news article
- Twitter resolves the redirect to news article
- Twitter hides link from Tweet and displays Twitter Card with news domain
- Attacker changes redirect to spam site
The Tweet now displays a legit looking Twitter Card with the news website domain, but actually goes to the scammer.
 
      jomo
jomo Aerdan
Aerdan kde
kde Ralf Stockmann
Ralf Stockmann Trolli Schmittlauch ????
Trolli Schmittlauch ???? Jörg Thalheim
Jörg Thalheim Anja
Anja Maxi von Böhmen ☑️
Maxi von Böhmen ☑️ nil
nil plomlompom
plomlompom 
          All senooken JP Social content and data are available under the
 All senooken JP Social content and data are available under the