Connect with us

Crypto

Microsoft India’s X account hijacked in Roaring Kitty crypto scam

Published

on

Microsoft India’s X account hijacked in Roaring Kitty crypto scam
Image: Midjourney

The official Microsoft India account on Twitter, with over 211,000 followers, was hijacked by cryptocurrency scammers to impersonate Roaring Kitty, the handle used by notorious meme stock trader Keith Gill.

Microsoft India’s X account has a gold check as an officially verified organization on the platform, lending the hijackers’ posts more legitimacy.

The threat actors take advantage of Gill’s recent comeback to lure potential victims and infect them with cryptocurrency wallet drainer malware.

They are now using Microsoft India’s hijacked account to reply to tweets, luring the company’s followers and other people on X to a malicious website (presaIe-roaringkitty[.]com) that would allegedly allow them to buy GameStop (GME) crypto as part of a so-called presale.

Phishing site pushed via Microsoft India's hijacked X account
Phishing site pushed via Microsoft India’s hijacked X account (BleepingComputer)

However, the threat actors would steal the assets of anyone who connects their cryptocurrency wallets to the site and authorizes transactions to the drainer service.

Many bot accounts are now also retweeting the hijacked account’s tweets, a tactic designed to artificially increase the malicious posts’ reach and trap even more victims.

Advertisement

Microsoft India hijacked account

​In recent months, X users have been targeted in a massive wave of account hijacks, leading to verified organizations falling victim to hacks promoting cryptocurrency scams and wallet drainers.

The U.S. Securities and Exchange Commission’s @SECGov account was also compromised after a SIM-swapping attack. The compromised account was later used to post a fake announcement about the long-awaited approval of Bitcoin exchange-traded funds (ETFs) on security exchanges, causing a temporary spike in Bitcoin prices.

X’s Safety team later also attributed the breach to a SIM-swapping attack that hijacked a phone number associated with the @SECGov account, noting that the SEC’s account did not have two-factor authentication (2FA) enabled at the time of the hack.

Previously, the X accounts for Netgear and Hyundai MEA were also hacked to promote sites designed to push crypto wallet drainers, while the account of Web3 security firm CertiK was also compromised days earlier for similar malicious purposes.

Since the beginning of the year, threat actors have been increasingly targeting verified government and business X accounts with ‘gold’ and ‘grey’ checkmarks to lend credibility to tweets that redirect users to phishing sites that promote cryptocurrency scams or spread crypto drainers.

Advertisement

X users also face a relentless barrage of malicious cryptocurrency ads, leading to scams, fake airdrops, and cryptocurrency and NFT drainers.

According to ScamSniffer blockchain threat experts, an X ad campaign used a single wallet drainer known as ‘MS Drainer’ to steal approximately $59 million worth of cryptocurrency from 63,000 people between March and November.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Crypto

Coinbase Security Impersonation Scheme Exposed as Authorities Claim Nearly $16M Was Siphoned

Published

on

Coinbase Security Impersonation Scheme Exposed as Authorities Claim Nearly M Was Siphoned
Authorities allege a sweeping crypto phishing operation that drained nearly $16 million from Coinbase users nationwide, underscoring how social engineering scams exploit trust, move funds across blockchains, and trigger aggressive enforcement by New York prosecutors.
Continue Reading

Crypto

Unmasking the Cryptocurrency Phishing Crisis – OneSafe Blog

Published

on

Unmasking the Cryptocurrency Phishing Crisis – OneSafe Blog

What if I told you that a single case could encapsulate the chaotic vulnerabilities of the cryptocurrency world? Enter Ronald Spektor, a figure now infamous for allegedly masterminding a phishing operation that siphoned away a staggering $16 million from naive Coinbase users. The fallout from this scheme plunges deep into the unsettling implications of trust in an era dominated by digital currencies—a stark reminder that the promise of crypto can quickly turn into a nightmare if we’re not careful.

The Dark Art of Cryptocurrency Phishing

Phishing has morphed into a sophisticated form of cybercrime, particularly within the cryptocurrency realm. Spektor’s alleged tactics involved posing as a trusted agent from Coinbase, using clever manipulation to lure unsuspecting users into handing over their hard-won crypto assets. The sheer audacity of exploiting trust is what amplifies the horror.

Picture this: victims, believing they’re engaging with legitimate support personnel, unwittingly become pawns in a malicious game. Spektor’s strategy revolved around deceptive communications that felt alarmingly real—a blend of phone calls and texts designed to strip away defenses. This situation underscores a grim reality: even the latest breakthroughs in blockchain technology cannot entirely shield users from the ploys of manipulative attackers. With reports indicating a relentless rise in account takeovers, the FBI urges continuous vigilance against such deceptions.

Emotional Toll on Victims

Beyond the dollar signs lies emotional wreckage. Victims of Spektor’s alleged scheme endured more than financial losses; their trust was shattered. The narrative here is compelling: years of labor invested in cryptocurrency can vanish in moments of misplaced faith. The ramifications are staggering—over 5,100 reported cases of account takeover fraud in 2025 alone, with losses soaring over $262 million. These numbers highlight a chilling truth—cybercriminals are thriving, particularly preying on those who lack the savvy to spot danger ahead.

A Glimmer of Hope Amid Regulatory Scrutiny

The escalating tide of cryptocurrency fraud thrusts platforms like Coinbase into the spotlight, facing mounting scrutiny over their security measures. As they work closely with law enforcement to reclaim stolen assets, tough questions about their safety protocols emerge. To navigate the ever-shifting landscape of crypto, exchanges must elevate their defensive stances in alignment with groundbreaking technologies.

Advertisement

Regulatory institutions are now taking an active role—pursuing comprehensive strategies to halt the proliferation of scams. This proactive approach extends beyond transaction verification; it’s also about nurturing user awareness and education. Financial institutions are encouraged to enhance protective measures for cryptocurrency users, crafting clearer guidelines to prevent fraud and restoring trust in tumultuous waters.

Innovative Approaches to Security

With evolving threats in the industry, experts call for a paradigm shift that prioritizes cybersecurity education alongside robust frameworks. Imagine harnessing real-time, AI-enhanced phishing detection mechanisms, especially for nascent Web3 startups. The key to protection? Cultivating a culture of awareness where users become savvy enough to recognize telltale signs and verify any critical communication through trusted sources, a necessity in an age where impersonation reigns.

The Road Ahead: A Call to Action

Spektor’s story serves as more than an isolated cautionary tale; it echoes a broader, systemic vulnerability interwoven within the cryptocurrency ecosystem. As technology advances, so do the methods of cybercriminals, reinforcing a critical insight: human error remains the weak link in this chain.

As we steer into the future, it is imperative that both investors and regulators understand and prioritize the safeguarding of security protocols across all platforms. To thrive, cryptocurrency exchanges must harmonize user-friendly transactions with unwavering security measures, crafting an environment where criminal operations struggle to take root.

Conclusion

The saga of Ronald Spektor signals an urgent call to arms against the pervasive threats encircling the cryptocurrency landscape. Strengthening security protocols and empowering an enlightened user base are not just advisable; they’re essential for survival. By championing vigilance and investing in advanced technological defenses, we stand a better chance of shielding investors and stabilizing the innovative yet fragile cryptocurrency market. As we confront the shadows cast by cybercrime, let us resolve to forge a more secure financial future that empowers rather than exploits.

Advertisement
Continue Reading

Crypto

USDC Enters Intuit’s Core Products With Circle Partnership as Stablecoins Move Mainstream

Published

on

USDC Enters Intuit’s Core Products With Circle Partnership as Stablecoins Move Mainstream
USDC is moving deeper into mainstream finance as Intuit partners with Circle to embed stablecoin payments across its platforms, expanding always-on, lower-cost digital money movement for consumers, small businesses, and global transactions.
Continue Reading

Trending