Twitter cryptocurrency scams: A hundred Elon Musks — and now Target
Credit to Author: Alex Perekalin| Date: Tue, 13 Nov 2018 17:02:06 +0000
“We are celebrating and giving away N bitcoins to our fans! Just transfer 0.01 BTC to the wallet below and we’ll return 0.1 BTC!” That’s what an average cryptocurrency scam looks like.
Of course, once you’ve transferred your cryptocurrency to the specified wallet, no one is going to pay you back. Those who posted the tweets were just scammers looking for easy money (and it’s rather hard to catch them; bitcoin provides some degree of anonymity). Who is going to fall for that? Actually, a lot of people — if the scam is presented to them by someone they trust.
A short history of Twitter cryptocurrency scams
Cryptocurrency scams first came to light when scammers pretending to be Elon Musk, CEO of Space X and Tesla, claimed to be giving away Ethereum for whatever reason, be it the launch of the new Space X rocket or the production of yet another Tesla car.
Elon Musk uses Twitter quite a lot for PR and communication, and he has more than 20 million followers. The scammers created accounts that borrowed his avatar and his name, as well as similar Twitter handles (say @elonmask instead of @elonmusk). Then, using these accounts, they replied to his original posts, promoting fake giveaways so that they looked like they came from Musk himself — unless, of course, you were paying close attention.
The technique worked, and cryptocurrency scams started gaining momentum. At some point, Twitter even started preemptively banning accounts that changed their name to Elon Musk.
Scammers then moved on to exploiting other Twitter celebrities such as Bill Gates, Pavel Durov (creator of vk.com and Telegram), Vitalik Buterin (creator of Ethereum cryptocurrency), and more. They also used bots that shared spam links, following other fake accounts, and producing retweets and likes to promote those cryptocurrency scams. Researchers from Duo Security discovered a large network of these bots that were following, liking, and retweeting each other.
At some point, scammers started hijacking verified accounts, using them to increase their posts’ persuasiveness. When yet another Ælon Müsk announced yet another crypto-giveaway, it looked significantly more convincing if verified accounts commented positively on it, claiming to have received their bitcoins. For example, recently hacked accounts include ones belonging to the Indian consulate in Frankfurt and to a consulting company called Capgemini.
Some scammers tried renaming other hacked verified accounts to look like Elon Musk (using letter “o” in Cyrillic or similar to keep Twitter from noticing and banning them) and using them to announce cryptocurrency scams and to add to the scams’ legitimacy.
The latest tech: Ads from verified accounts
In this stage of the cryptocurrency scam evolution, perpetrators began replacing tweets with Twitter ads posted in the name of verified (but fake) accounts of the sort discussed in the previous section. It makes sense: Twitter ads have no comments, so there’s no way to warn potential victims.
And now, cryptocurrency scammers have gone even further. Their latest technique makes those scams even more convincing. Recently, they hacked Target’s Twitter account — but instead of posting a normal tweet (which would be spotted quickly by Target’s employees and followers), the scammers decided to run an ad promoting their cryptocurrency scam.
[twitter-cryptocurrency-scams-target]
It looked really convincing:
- It was an official ad;
- It was from Target’s official, verified account.
Target is unlikely to be the last victim of this kind of attack, so stay alert and don’t trust any cryptocurrency giveaways, no matter who’s promoting them.