{"id":24560,"date":"2018-11-13T12:02:06","date_gmt":"2018-11-13T17:02:06","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=24560"},"modified":"2019-11-15T06:32:16","modified_gmt":"2019-11-15T11:32:16","slug":"twitter-cryptocurrency-scams","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/24560\/","title":{"rendered":"Twitter cryptocurrency scams: A hundred Elon Musks \u2014 and now Target"},"content":{"rendered":"<p>\u201cWe are celebrating and giving away N bitcoins to our fans! Just transfer 0.01 BTC to the wallet below and we\u2019ll return 0.1 BTC!\u201d That\u2019s what an average cryptocurrency scam looks like.<\/p>\n<p>Of course, once you\u2019ve transferred your cryptocurrency to the specified wallet, no one is going to pay you back. Those who posted the tweets were just scammers looking for easy money (and it\u2019s rather hard to catch them; bitcoin provides some degree of anonymity). Who is going to fall for that? Actually, a lot of people \u2014 if the scam is presented to them by someone they trust.<\/p>\n<h3>A short history of Twitter cryptocurrency scams<\/h3>\n<p>Cryptocurrency scams first came to light when scammers pretending to be Elon Musk, CEO of Space X and Tesla, claimed to be giving away Ethereum for whatever reason, be it the launch of the new Space X rocket or the production of yet another Tesla car.<\/p>\n<p>Elon Musk uses Twitter quite a lot for PR and communication, and he has more than 20 million followers. The scammers created accounts that borrowed his avatar and his name, as well as similar Twitter handles (say @elonmask instead of @elonmusk). Then, using these accounts, they replied to his original posts, promoting fake giveaways so that they looked like they came from Musk himself \u2014 unless, of course, you were paying close attention.<\/p>\n<p>The technique worked, and cryptocurrency scams started gaining momentum. At some point, Twitter even <a href=\"https:\/\/www.huffingtonpost.com\/entry\/twitters-lock-elon-musk-name-nazi-ban-possible_us_5b5f268ce4b0b15aba9b25c1\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">started preemptively banning accounts that changed their name to Elon Musk<\/a>.<\/p>\n<p>Scammers then moved on to exploiting other Twitter celebrities such as Bill Gates, Pavel Durov (creator of vk.com and Telegram), Vitalik Buterin (creator of Ethereum cryptocurrency), and more. They also used bots that shared spam links, following other fake accounts, and producing retweets and likes to promote those cryptocurrency scams. Researchers from Duo Security <a href=\"https:\/\/www.kaspersky.com\/blog\/hunting-twitter-bots\/23437\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">discovered a large network of these bots<\/a> that were following, liking, and retweeting each other.<\/p>\n<p>At some point, scammers started hijacking verified accounts, using them to increase their posts\u2019 persuasiveness. When yet another \u00c6lon M\u00fcsk announced yet another crypto-giveaway, it looked significantly more convincing if verified accounts commented positively on it, claiming to have received their bitcoins. For example, recently hacked accounts include ones belonging to the Indian consulate in Frankfurt and to a consulting company called Capgemini.<\/p>\n<p>Some scammers tried renaming other hacked verified accounts to look like Elon Musk (using letter \u201co\u201d in Cyrillic or similar to keep Twitter from noticing and banning them) and using them to announce cryptocurrency scams and to add to the scams\u2019 legitimacy.<\/p>\n<h3>The latest tech: Ads from verified accounts<\/h3>\n<p>In this stage of the cryptocurrency scam evolution, perpetrators began replacing tweets with Twitter ads posted in the name of verified (but fake) accounts of the sort discussed in the previous section. It makes sense: Twitter ads have no comments, so there\u2019s no way to warn potential victims.<\/p>\n<p>And now, cryptocurrency scammers have <a href=\"https:\/\/twitter.com\/gcluley\/status\/1062301244646154241\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">gone even further<\/a>. Their latest technique makes those scams even more convincing. Recently, they compromised Target\u2019s Twitter account \u2014 but instead of posting a normal tweet (which would be spotted quickly by Target\u2019s employees and followers), the scammers decided to run an ad promoting their cryptocurrency scam.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/11\/14003404\/twitter-cryptocurrency-scams-target-1.jpg\"><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/11\/14003404\/twitter-cryptocurrency-scams-target-1.jpg\" alt=\"An ad from official Target's account promoting cryptocurrency giveaways\" width=\"1500\" height=\"1268\" class=\"aligncenter size-full wp-image-24587\"><\/a><\/p>\n<p>It looked really convincing:<\/p>\n<ul>\n<li>It was an official ad;<\/li>\n<li>It was from Target\u2019s official, verified account.<\/li>\n<\/ul>\n<p>Target is unlikely to be the last victim of this kind of attack, so stay alert and don\u2019t trust any cryptocurrency giveaways, no matter who\u2019s promoting them.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-trial-generic\">\n<h3>Update, November, 15<\/h3>\n<p>Just as we predicted, Target was not the last victim: Somebody <a href=\"https:\/\/twitter.com\/olihough86\/status\/1062429109664522240\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">has compromised<\/a> the Twitter account of Google\u2019s G Suite collaboration and productivity apps and used it for the very same purpose, publishing ads for yet another cryptocurrency scam.<\/p>\n<p>It\u2019s also noteworthy that people from communities not related to IT and tech are starting to see cryptoscams as well. Malefactors have hacked the Twitter accounts of an Italian tennis player, cosmetics store The Body Shop, a Spanish university sports team, and many more.<\/p>\n<p>That brings us to another piece of advice. If you have a Twitter account (especially a verified one), take the time to think about its security: Make sure that you have a long and unique password and that you\u2019ve enabled two-factor authentication. You can read more about <a href=\"https:\/\/www.kaspersky.com\/blog\/twitter-security\/11860\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">how to set up Twitter securely in this post<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Twitter cryptocurrency scams are becoming more and more advanced and convincing, with scammers using new techniques and some heavy artillery.<\/p>\n","protected":false},"author":675,"featured_media":24580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2683],"tags":[2640,726,513,422,83],"class_list":{"0":"post-24560","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-cryptocurrencies","10":"tag-scam","11":"tag-social-engineering","12":"tag-threats","13":"tag-twitter"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/24560\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/twitter-cryptocurrency-scams\/14601\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/12222\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/5981\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/16530\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/twitter-cryptocurrency-scams\/14738\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/twitter-cryptocurrency-scams\/13653\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/twitter-cryptocurrency-scams\/17321\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/twitter-cryptocurrency-scams\/16579\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/twitter-cryptocurrency-scams\/21664\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/twitter-cryptocurrency-scams\/11156\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/twitter-cryptocurrency-scams\/11081\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/twitter-cryptocurrency-scams\/10037\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/twitter-cryptocurrency-scams\/18100\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/twitter-cryptocurrency-scams\/21980\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/twitter-cryptocurrency-scams\/17599\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/twitter-cryptocurrency-scams\/21474\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/twitter-cryptocurrency-scams\/21472\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/scam\/","name":"scam"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/675"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=24560"}],"version-history":[{"count":10,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24560\/revisions"}],"predecessor-version":[{"id":29593,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/24560\/revisions\/29593"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/24580"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=24560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=24560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=24560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}