Cyber Attacks

Security firm Certik’s X account hacked

0

The Twitter account of blockchain security firm CertiK was hacked to redirect the company’s followers to a malicious website pushing a cryptocurrency wallet drainer.

CertiK’s gold-verified X account was compromised in a social media phishing attack by a threat actor to share a link to a malicious website.

Certik warned via its X (formerly Twitter) account “Certik Alert” that it was investigating reports of a compromise on its main account. They asked the users to not interact with any posts until the account is secured.

The phishing link was up for just 15 minutes and upon detecting the breach, the firm immediately deleted the related tweets. It’s unclear whether any of the company’s 342,000 followers clicked through.

A subsequent investigation found this to be part of a large-scale ongoing social engineering campaign that already led to the compromise of many other accounts.

The phishing message itself appeared to spoof crypto wallet management firm Revoke, with a fake security alert taking users to a spoofed Revoke site. This contained crypto-drainer malware designed to transfer digital currency from victims’ accounts without their consent.

Revoke was forced to publish its own post on Friday morning to warn users of the scam.

The phishing attack that compromised Certik involved the legitimate but dormant account of a Forbes journalist that was hijacked and used to message the security vendor.

The company encouraged those who were affected during this incident to reach out.

Image Credits : The Crypto Times

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Ivanti warns critical EPM bug lets hackers hijack enrolled devices

Previous article

Turkish Sea Turtle APT target Dutch ISPs, telcos

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *