The Twitter account of American cybersecurity firm and Google subsidiary Mandiant was hijacked earlier today to impersonate the Phantom crypto wallet and share a cryptocurrency scam.
“We are aware of the incident impacting the Mandiant X account and are working to resolve the issue,” a Mandiant spokesperson told BleepingComputer.
After getting control, the attacker renamed it to @phantomsolw and promoted a fake website impersonating the Phantom crypto wallet and promising to distribute free $PHNTM tokens as part of an airdrop.
In tests by BleepingComputer, those who click the ‘Claim Aidrop’ button and don’t have the Phantom wallet installed will get redirected to the legitimate site where they’re prompted to install it.
Once installed, it will try to automatically drain the targets’ cryptocurrency wallets. However, the Phantom Wallet now warns that the scammers’ website is part of a phishing attack.
“Phantom believes this website is malicious and unsafe to use. We have disabled the ability to interact with it in order to protect you and your funds,” the warning says.
The threat actor behind this attack has since deleted the scam tweet and is now using it to troll Mandiant, saying, “Sorry, change password please.” and “Check bookmarks when you get account back.”
As shown in the screenshot above, the attacker is now retweeting posts from the official Phantom account, including ones advising users to “never rush into clicking links,” likely to add legitimacy to future crypto-scam posts.
Mandiant’s original Twitter handle, @mandiant, now displays a “This account doesn’t exist. Try searching for another.” error message.
This article was originally published by a www.bleepingcomputer.com . Read the Original article here. .
Disclaimer:The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website’s content as such. BitcoinNews.live does not recommend that any cryptocurrency should be bought, sold, or held by you. Do conduct your own due diligence and consult your financial advisor before making any investment decisions.