logo

‘Yes, this is real’: hackers targeting high-profile X accounts blur fact and fiction

ID: 8a472b16-35d8-5a09-a585-ebf511dfc84c

STIX ID: report--8a472b16-35d8-5a09-a585-ebf511dfc84c

Feed Name: The Record from Recorded Future News

Threat Score
60/100

Date Published: 2025-02-03

Date Updated: 2026-05-01

...
...

SentinelOne researchers report an active phishing campaign targeting high-profile X/Twitter accounts to hijack them and promote cryptocurrency scams. The attackers use credential-phishing emails and account lockouts to post fraudulent crypto links, and SentinelOne traced parts of the infrastructure to an IP tied to a Belize VPS provider (Dataclub) and malicious domains registered through a Turkish hosting provider (Turkticaret); the report urges unique passwords, multi-factor authentication, and caution with login-related emails and links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.