{"id":18143,"date":"2022-02-02T11:12:30","date_gmt":"2022-02-02T19:12:30","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11876\/"},"modified":"2022-02-02T11:12:30","modified_gmt":"2022-02-02T19:12:30","slug":"news-11876","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11876\/","title":{"rendered":"Actor&#8217;s verified Twitter profile hijacked to spam NFT giveaways"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 31 Jan 2022 11:37:04 +0000<\/strong><\/p>\n<p>When we refer to hijacked verified profiles on Twitter, it\u2019s most commonly some sort of Elon Musk themed scam. The hijackers compromise the account, switch the picture to Elon, and then start spamming cryptocurrency links. Alternatively, they may keep the account as it is and spam images claiming Elon has approved a giveaway or <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/verified-twitter-accounts-hacked-in-580k-elon-musk-crypto-scam\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">something similar<\/a>.<\/p>\n<p>Well, times have changed on the big blue bird app. Whisper it, but Elon tributes may no longer be the hottest way on the block to earn some scam money. Instead, we\u2019re seeing verified profiles compromised to promote and sell NFTs instead.<\/p>\n<h2>Forging a new career in pixel art<\/h2>\n<p>At some point on Thursday a verified profile belonging to Siobh\u00e1n McSweeney, well known Irish actor, started to behave a little unusually. That is to say, promoting a range of pixel art cats known as \u201cGrumpyKatz\u201d.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"54071\" data-permalink=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/attachment\/cat2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2.jpeg\" data-orig-size=\"593,903\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"cat2\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2-197x300.jpeg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2-394x600.jpeg\" loading=\"lazy\" width=\"394\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2-394x600.jpeg\" alt=\"\" class=\"wp-image-54071\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2-394x600.jpeg 394w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2-197x300.jpeg 197w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat2.jpeg 593w\" sizes=\"auto, (max-width: 394px) 100vw, 394px\" \/><\/figure>\n<\/div>\n<p>The tweet reads as follows:<\/p>\n<p><em>Giveaway time!<\/em><\/p>\n<p><em>I am working with @grumpykatznfts to giveaway 15 SOL ($1500)<\/em><\/p>\n<p><em>To enter:<\/em><\/p>\n<ul>\n<li><em>Follow me &amp; @GrumpyKatzNFT<\/em><\/li>\n<li><em>Like &amp; RT<\/em><\/li>\n<li><em>Tag 3 friends<\/em><\/li>\n<\/ul>\n<p>We don&#8217;t know if the linked pixel art project is &#8220;genuine&#8221; or not, as there&#8217;s very little to go on from the <a href=\"https:\/\/twitter.com\/GrumpyCatzNFTs\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">profile itself<\/a>. Another tweet (now deleted) suggested people should send a direct message to the account. Whoever was running this scam would likely have phished hopefuls via the hijacked Twitter account.<\/p>\n<p>A short while after, the profile finally completed its full transformation. Behold the weirdly drawn ape of doom set as the profile picture:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"54072\" data-permalink=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/attachment\/cat3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3.png\" data-orig-size=\"621,909\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"cat3\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3-205x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3-410x600.png\" loading=\"lazy\" width=\"410\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3-410x600.png\" alt=\"\" class=\"wp-image-54072\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3-410x600.png 410w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3-205x300.png 205w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/01\/cat3.png 621w\" sizes=\"auto, (max-width: 410px) 100vw, 410px\" \/><\/figure>\n<\/div>\n<p>You\u2019ll notice the bio blurb has been altered to fit in with the general NFT theme taking place. It says:<\/p>\n<p><em>Building an NFT community | 450,000 supporters | NFT promoter | DM for promo<\/em><\/p>\n<p>The profile location has also been set to \u201cMetaverse\u201d, because of course it has.<\/p>\n<h2>Getting up to some monkey business<\/h2>\n<p>Followers of the actor were initially a bit surprised by the sudden interest in all things cryptocurrency. Had she decided to hop on the bandwagon? Or was something else at work? People weren\u2019t sure and there was no 100% confirmed answer until a little earlier today.<\/p>\n<p>This blog is safe for work so if you wish to see her, um, very <em>enthusiastic<\/em> condemnation of the account compromise, click <a href=\"https:\/\/twitter.com\/siobhni\/status\/1487007708205178880\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">here<\/a>. At time of writing, some of the NFT\/metaverse related Tweets are still on her profile.<\/p>\n<h2>What caused this, and how can you protect your Twitter account?<\/h2>\n<p>As to how it happened, there\u2019s no indication just yet.<\/p>\n<p>Verified profile accounts need to have two-factor authentication (2FA) enabled to be verified in the first place. But we\u2019ve seen enough sneaky examples of people bypassing 2FA on different platforms previously. <\/p>\n<p>Twitter offers a variety of options where it\u2019s concerned: <a href=\"https:\/\/help.twitter.com\/en\/managing-your-account\/two-factor-authentication\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">mobile, app, and security key<\/a>. Perhaps the actor is using SMS codes and somebody performed a SIM swap attack. Maybe she uses an auth app but was taken to a phishing page which also asks for the time sensitive code.<\/p>\n<p>I suspect we won\u2019t find out. Even so, this is a good time to go check your login and verification settings on Twitter whether verified or not. You don\u2019t want to accidentally wander into whatever currently passes for a metaverse, no matter how many free cats they claim to be giving away.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/\">Actor&#8217;s verified Twitter profile hijacked to spam NFT giveaways<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 31 Jan 2022 11:37:04 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/' title='Actor's verified Twitter profile hijacked to spam NFT giveaways'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2013\/10\/photodune-5417415-twitter-s.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>We&#8217;re seeing verified Twitter profiles compromised to push NFT sales and giveaways. How did it happen, and how can you protect yourself?<\/p>\n<p>Categories: <a href=\"https:\/\/blog.malwarebytes.com\/category\/malwarebytes-news\/\" rel=\"category tag\">Malwarebytes news<\/a><\/p>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/ape\/\" rel=\"tag\">ape<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/cat\/\" rel=\"tag\">cat<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/hijacked\/\" rel=\"tag\">hijacked<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/metaverse\/\" rel=\"tag\">Metaverse<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/nft\/\" rel=\"tag\">NFT<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/twitter\/\" rel=\"tag\">twitter<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/' title='Actor's verified Twitter profile hijacked to spam NFT giveaways'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2022\/01\/actors-verified-twitter-profile-hijacked-to-spam-nft-giveaways\/\">Actor&#8217;s verified Twitter profile hijacked to spam NFT giveaways<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[24754,24755,24756,10546,24757,24758,10518,454],"class_list":["post-18143","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-ape","tag-cat","tag-hijacked","tag-malwarebytes-news","tag-metaverse","tag-nft","tag-spam","tag-twitter"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18143"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18143\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}