Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hacked Mandiant X Account Abused for Cryptocurrency Theft

Mandiant’s account on X, formerly Twitter, was hacked and used to lure users to a cryptocurrency phishing site.

Mandiant’s account on the social media platform X, formerly Twitter, was hacked on Wednesday and abused to lure users to a website designed to steal cryptocurrency from victims. 

The account of Mandiant, which is part of Google Cloud, was renamed to ‘Phantom’ and its profile image and description were updated to appear affiliated with the legitimate Phantom cryptocurrency wallet.

Messages posted on the hijacked account promoted a website hosted at claim-phntm.com, which claimed to distribute cryptocurrency tokens through an airdrop. In reality, the site is designed to steal users’ cryptocurrency. 

The hacked account was later used to troll the cybersecurity firm, telling it to change its password.

Mandiant immediately took action to recover the account, but the hacker regained control at one point during the recovery process. 

Researchers at MalwareHunterTeam, who have been monitoring the incident, noted that it did not take Mandiant long to recover the account, considering that it has taken some X users days or even more to regain complete control of their account following a hacker attack.

While the hacker posted a message urging Mandiant to change its password, in many cases social media account hijacking involves abusing a third-party service rather than a direct attack on the account. 

SecurityWeek has reached out to Mandiant for more information and will update this article if the company provides additional details.  

Major web browsers currently flag the domain promoted by the hacker as a potential phishing site. 

Advertisement. Scroll to continue reading.

This incident occurred just as cybersecurity company CloudSEK published a report on X Gold accounts being sold on the dark web, in some cases for thousands of dollars. These accounts can be highly useful for phishing, disinformation and other types of campaigns.

Update: Mandiant told SecurityWeek that it’s investigating the incident.

“We are aware of the incident that impacted the Mandiant X account and are conducting a thorough investigation. We’ve since regained control and the account has been restored,” said a Mandiant spokesperson.

Related: Ukraine Cracks Down on Group Selling Hacked Accounts to Pro-Russia Propagandists

Related: Targeted Links Used to Steal Tens of Millions in Global Scam Campaign

Related: Indian PM’s Twitter Hacked Again by Crypto Scammers

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cohesity has hired former DoD Chief Digital and Artificial Intelligence Officer (CDAO) Dr. Craig Martell as Chief Technology Officer.

Ex-NSA chief Paul Nakasone has been appointed founding director of the Institute for National Defense and Global Security at Vanderbilt University.

Garo Doudian has joined NextGen Healthcare as Chief Information and Security Officer (CIO/CISO).

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.