216.73.217.80

New Finance Scam Discovered Abusing Niche X/Twitter Advertising Loophole

· Published 09/05/2025 17:49 · Modified 09/05/2025 17:55

Export JSON

Essential information

Published
09/05/2025 17:49
Modified
09/05/2025 17:55
Tags
2025-05-09 apple brand impersonation cryptocurrency domain redirection url spoofing x/twitter
Related entities
65 observables, 7 techniques (mitre), 9 others

Description

A new financial scam has been uncovered that exploits a loophole in 's advertising display URL feature. The scam spoofs legitimate domains like CNN while directing users to a scam website impersonating 's brand. The fraudulent site promotes a fake 'iToken' and includes false endorsements from 's CEO. Nearly 90 similar sites dating back to 2024 have been identified, likely operated by the same threat actor group. The campaign uses various tactics including , , and to lure victims. Multiple wallets are provided for payments, and the scam includes a loyalty program to encourage larger investments. The threat actors are also reusing specific files and favicons across their network of malicious domains.

External references