Google-owned security firm Mandiant spent a number of hours making an attempt to regain management of its account on X (previously generally known as Twitter) on Wednesday after an unknown scammer hijacked it and used it to unfold a hyperlink that tried to steal cryptocurrency from individuals who clicked on it.
“We’re conscious of the incident impacting the Mandiant X account and are working to resolve the problem,” firm officers wrote in a press release. “We have since regained management over the account and are presently engaged on restoring it.” The assertion didn’t reply questions asking if the firm had decided how the account was compromised.
The hacked Mandiant account was initially used to masquerade as one belonging to Phantom, an organization that gives a pockets for storing cryptocurrency. Posts on X inspired individuals to go to a malicious web site to see if their pockets was one in every of 250,000 that have been eligible for an award of tokens. Over a number of hours, X workers performed tug-of-war with the unknown scammer, with rip-off posts being eliminated solely to reappear, in line with individuals who adopted the occasions.
Ultimately, the scammer modified the @mandiant username and reappeared below a brand new username. After utilizing the account to advertise a faux web site impersonating Phantom and promising free tokens, it posted the cryptic message: “examine bookmarks while you get account again.” It additionally chided Mandiant to “change password please.”
At the time this put up went dwell on Ars, the Mandiant profile displayed the message “This account doesn’t exist.”
Mandiant is one in every of the main security corporations and finest recognized for serving to shoppers examine and recuperate from main community compromises. That vantage level offers it main insights into menace actors, a lot of them backed by nation-states, and the usually beforehand unknown ways, methods, and procedures they use to compromise the security of a few of the world’s strongest and well-resourced organizations. Google bought Mandiant in 2022 for $5.four billion, which, at the time, was its second-biggest acquisition ever.
Many questions stay about Mandiant’s measures to safe its X account. Amongst them: Was it protected by a powerful password and any type of two-factor authentication? Final month, somebody claimed to have found the social media website was susceptible to a “mirrored XSS,” a kind of vulnerability that may generally be used to compromise the security of accounts when a reliable consumer presently logged in clicks on a malicious hyperlink in a distinct browser tab. The consumer stated they reported the vulnerability via reliable channels however that the submission didn’t qualify below the X bug bounty program.
“Clicking a crafted hyperlink or going to some crafted internet pages would enable attackers to take over your account (posting, liking, updating your profile, deleting your account, and so forth.),” Chaofan Shou, a College of California at Berkeley Ph.D. candidate, wrote final month.
Makes an attempt to succeed in Phantom for remark have been unsuccessful.