Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Scammers Promote Fake Cryptocurrency Giveaways Via Twitter Ads

Scammers Promote Fake Cryptocurrency Giveaways Via Twitter Ads

Threat actors have started to use ‘Promoted’ tweets, otherwise known as Twitter ads, to spread cryptocurrency giveaway scams.

For some time, BleepingComputer has been reporting on scammers hacking into verified Twitter accounts to promote fake cryptocurrency giveaway scams. These scams pretend to be from well-known people or companies, such as Elon Musk, Tesla, Gemini Exchange, and, more recently, Chamath Palihapitiya, and Social Capital.

These scams have been incredibly successful for the threat actors, with one round of scams generating over $580,000 in a single week.

As these scams continue to generate revenue, the threat actors have also begun to target other cryptocurrencies that have recently become popular, such as Dogecoin.

Move over hacks. Hello, ads!

To promote their services and content, Twitter users can ‘promote’ an existing tweet by paying to have it shown to other users in their Twitter feeds.

Promoting a tweet on Twitter
Promoting a tweet on Twitter

This week, security researchers zseano, Jake, and MalwareHunterTeam have monitored a new trend used by the cryptocurrency scammers – taking out Twitter advertisements to promote their scams.

Also Read: What Do 4 Messaging Apps Get From You? Read The iOS Privacy App Labels

As you can see from the above images, both tweets are being promoted by Twitter and contain URLs to cryptocurrency giveaways.

When creating the tweets, the scammers break up the URL so that Twitter’s ad fraud detection algorithms do not detect them.

Like the previous giveaway scams, these URLs lead to fake Medium pages pretending to be from Tesla, Social Capital, and Gemini Exchange that contain further links to the actual giveaway sites.

Fake Elon Musk Medium post
Fake Elon Musk Medium post

The giveaway sites’ final landing pages are commonly Tesla, or Elon Musk-themed and contain a Bitcoin, Ethereum, or Dogecoin address that users are told to send coins. In return, the scammers state that the sender will receive double the amount that they sent.

Fake Tesla giveaway landing page
Fake Tesla giveaway landing page

From looking at only a few of the scams, the Bitcoin and Ethereum addresses used have generated a total of $39,628.06 so far.

Also Read: Key PDPA Amendments 2019/2020 You Should Know

Some of the cryptocurrency addresses used in these scams are listed below:

Ethereum:

  • 0xc77Ec8E5bbB723e6cEa13fD33bfF53262bb02b86 – 0.118890894374483125 Ether
  • 0xE1a6d4699Bd6520ADdEcD46b52dd2eFC833142ED – 0.915305158603885603 Ether

Bitcoin:

  • 1MoP7JTQuJE8K9pv8mV9uwo5efCgRtLYNU – 0.02196955 BTC
  • 1MUSK2xaUCQmdEM8DrUJQ9RSgTdLqnKium – 0.54653960 BTC
  • 1Musk7UAHXM6YBtccdaqK7ttsRxSTUSDVH – 0.11815051 BTC

Unfortunately, the scammers currently use many more cryptocurrency addresses, so the amount generated is probably far more significant.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us