Credit:
The attack spreads via messages with the text "This you????" followed by a link that sends the user to a fake Twitter login page. Don't fall for the trick. If you enter your credentials there, you're not actually logging into Twitter, you're just sending your username and password to the attacker.
If you suspect you've fallen victim of this attack, you should change your Twitter password immediately. Check out a video demonstration of the attack (created by Sophos) below.