{"id":121,"date":"2021-03-04T07:36:33","date_gmt":"2021-03-04T07:36:33","guid":{"rendered":"http:\/\/15.207.161.156\/blog\/2021\/03\/04\/scam-alert-high-profile-twitter-accounts-targeted-by-attackers-to-spread-cryptocurrency-scam\/"},"modified":"2021-03-04T07:36:33","modified_gmt":"2021-03-04T07:36:33","slug":"scam-alert-high-profile-twitter-accounts-targeted-by-attackers-to-spread-cryptocurrency-scam","status":"publish","type":"post","link":"https:\/\/testblog.prodmarc.com\/index.php\/2021\/03\/04\/scam-alert-high-profile-twitter-accounts-targeted-by-attackers-to-spread-cryptocurrency-scam\/","title":{"rendered":"SCAM ALERT !! High profile Twitter accounts targeted by attackers to spread Cryptocurrency Scam"},"content":{"rendered":"<div>\n<figure><img src=\"https:\/\/static.wixstatic.com\/media\/2c92e2_bf9c4a93d5ec45938689fad7457d434e~mv2.png\/v1\/fit\/w_1000,h_1000,al_c,q_80\/file.png\" \/><\/figure>\n<p>Verified Twitter accounts of high-profile individuals and companies like Apple, Bill Gates, Joe Biden, and Elon Musk assured followers a huge pay out if they just send bitcoin to a block chain address \u2014 presumably to contribute to the COVID-19 relief funds; after the social media platform was breached.<\/p>\n<p>Affected accounts belong to businesses and individuals involving Apple, Bitcoin, Barack Obama, CashApp, CoinDesk, Jeff Bezos, Elon Musk, Coinbase, Uber, Bill Gates, Joe Biden, Michael Bloomberg, and Kanye West. A few account owners quickly took control of their profiles and deleted the tweets.<\/p>\n<p>The message from some accounts read, \u201cI am giving back to my community due to Covid-19,\u201d noting that the offer was valid for only 30 minutes. Bill Gates&#8217; account promised to send $2,000 back to people who sent $1,000. A similar message appeared on Elon Musk&#8217;s account, with a tweet saying, &#8220;I&#8217;ll double any BTC payment sent to my BTC address for the next hour,&#8221; followed by a hyperlink.<\/p>\n<figure><img src=\"https:\/\/static.wixstatic.com\/media\/2c92e2_12aa04e5fcfc463092eafd1193277a09~mv2.png\/v1\/fit\/w_789,h_373,al_c,q_80\/file.png\" \/><\/figure>\n<figure><img src=\"https:\/\/static.wixstatic.com\/media\/2c92e2_2b8e5056218647fcad71bdcac9864cc6~mv2.jpg\/v1\/fit\/w_728,h_380,al_c,q_80\/file.png\" \/><\/figure>\n<p>Cyber security firm RiskIQ has published a <a href=\"https:\/\/pastebin.com\/h64CK3CG\" target=\"_blank\" rel=\"noopener\">list of domains<\/a> connected to the scam, giving further insight into the magnitude of people and corporations targeted. It&#8217;s ambiguous how widespread the incident is, but so far, the scammers have been successful in collecting more than $103,000.<\/p>\n<p>Security researchers also found that the attackers had not only taken over the victims&#8217; accounts, but also changed the email address associated with the accounts, making it tougher for the real user to regain access.<\/p>\n<p>Twitter said in an official <a href=\"https:\/\/twitter.com\/TwitterSupport\/status\/1283518038445223936\" target=\"_blank\" rel=\"noopener\">statement<\/a>: &#8220;We are aware of a security incident impacting accounts Twitter accounts. We are investigating and taking steps to fix it. We will update everyone shortly&#8221;. As a part of the company&#8217;s remediation efforts, verified accounts, used to promote the scam, have been blocked from tweeting.<\/p>\n<p>Hours later, twitter confirmed that the hack was a result of a social engineering attack by which the hackers targeted some of their employees with access to internal systems and tools.<\/p>\n<figure><img src=\"https:\/\/static.wixstatic.com\/media\/2c92e2_53bcb495f7ff4f9183469d79052e1d80~mv2.png\/v1\/fit\/w_591,h_295,al_c,q_80\/file.png\" \/><\/figure>\n<p>Once aware of the incident, twitter immediately locked the affected accounts and removed tweets posted by the attackers. Internally, Twitter said it has also taken steps to limit access to internal systems and tools while the investigation is ongoing.<\/p>\n<p>Whereas in other cases, the attackers have bribed workers to leverage tools over individual users, in this case social engineering has been used to gain access that has led to takeovers of some of the biggest accounts on the social media platform and tweeted bitcoin related scams in an effort to generate income.<\/p>\n<p><strong>References:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/twitter-accounts-of-elon-musk-bill-gates-and-others-hijacked-to-promote-crypto-scam\/\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/www.zdnet.com\/article\/twitter-accounts-of-elon-musk-bill-gates-and-others-hijacked-to-promote-crypto-scam\/<\/u><\/a><\/li>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/twitter-confirms-internal-tools-used-in-bitcoin-promoting-attack\/\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/www.zdnet.com\/article\/twitter-confirms-internal-tools-used-in-bitcoin-promoting-attack\/<\/u><\/a><\/li>\n<li><a href=\"https:\/\/techcrunch.com\/2020\/07\/15\/twitter-accounts-hacked-crypto-scam\/?web_view=true\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/techcrunch.com\/2020\/07\/15\/twitter-accounts-hacked-crypto-scam\/?web_view=true<\/u><\/a><\/li>\n<li><a href=\"https:\/\/www.scmagazine.com\/home\/security-news\/biden-gates-twitter-hacked-in-cryptocurrency-scam\/\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/www.scmagazine.com\/home\/security-news\/biden-gates-twitter-hacked-in-cryptocurrency-scam\/<\/u><\/a><\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2020\/07\/verified-twitter-hacked.html\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/thehackernews.com\/2020\/07\/verified-twitter-hacked.html<\/u><\/a><\/li>\n<li><a href=\"https:\/\/pastebin.com\/h64CK3CG\" target=\"_blank\" rel=\"noopener\"><u>https:\/\/pastebin.com\/h64CK3CG<\/u><\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Verified Twitter accounts of high-profile individuals and companies like Apple, Bill Gates, Joe Biden, and Elon Musk assured followers a huge pay out if they just send bitcoin to a block chain address \u2014 presumably to contribute to the COVID-19 relief funds; after the social media platform was breached. Affected accounts belong to businesses and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":588,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_mi_skip_tracking":false},"categories":[1],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/posts\/121"}],"collection":[{"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/comments?post=121"}],"version-history":[{"count":0,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/posts\/121\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/media?parent=121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/categories?post=121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testblog.prodmarc.com\/index.php\/wp-json\/wp\/v2\/tags?post=121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}