Twitter users having a hard time with their bitcoin wallets should be wary of accounts that offer to fix them. Attackers are using this social engineering method to trick cryptocurrency owners into forking over their wallet recovery codes.

Malwarebytes spotted multiple Twitter accounts seeking to take advantage of people searching for a bitcoin wallet recovery tool. The security firm described those efforts as ‘low maintenance’. That means all attackers needed to do was to set up a profile. Then, they could tweet out a link to a phishing landing page and wait.

Read on to learn what to watch out for when it comes to this type of social engineering.

Breaking the First Rule of Crypto

In its analysis of the campaign, Malwarebytes found that digital attackers targeted Trust Wallet, an app that enables users to send, receive and store bitcoin, as well as other cryptocurrencies.

The attackers targeted real customer support threads on Twitter to trick users into clicking on a link. As part of the social engineering, another attack profile claimed the fake customer support team solved their problem.

But that link didn’t direct anyone to customer support. Instead, it sent them to a phishing landing page that asked them to describe their issue. It then asked users to submit their recovery phrase for their account.

That’s a bad idea.

In late April 2021, the official Twitter account for this application warned users to always remember the “first rule of crypto”, that is, to never give out their recovery phrase. This is exactly the kind of rule social engineering attacks attempt to get around. This recovery code, which can consist of up to 12 words, is how users regain their accounts and their stored cryptocurrency if they lose access. In the wrong hands, the recovery phrase could enable attackers to drain their victims’ accounts.

Other profiles involved in this campaign auto-responded to tweets seeking help from the official account. In their responses, those profiles spammed out links to fake forms hosted on Google Docs. Of course, these also sought to steal users’ recovery phrases.

Other Twitter Social Engineering Scams

Twitter phishing in general and customer support DM slide scams, in particular, have been used numerous times in the past few years.

Digital attackers used the same social engineering technique in April 2014. In that specific attack, they posed as customer support representatives for EA Sports on Twitter. They lead users to a fake website designed to steal access to EA Sports games. Attackers used the same social phishing tactics in 2016 to go after Natwest customers’ bank logins.

How to Defend Against Twitter Social Engineering

Organizations can defend their employees against the types of Twitter social engineering discussed above by investing in their security awareness training programs. They can specifically use phishing simulations that emphasize how unlikely it is that official companies will ever use a form hosted on Google Docs to process official customer support requests. In addition, regularly remind users not to give out their passwords or other secrets to anyone.

More from News

Securing critical infrastructure with the carrot and stick

4 min read - It wasn’t long ago that cybersecurity was a fringe topic of interest. Now, headline-making breaches impact large numbers of everyday citizens. Entire cities find themselves under cyberattack. In a short time, cyber has taken an important place in the national discourse. Today, governments, regulatory agencies and companies must work together to confront this growing threat. So how is the federal government bolstering security for critical infrastructure? It looks like they are using a carrot-and-stick approach. Back in March 2022, the…

650,000 cyber jobs are now vacant: How to tackle the risk

4 min read - How far is the United States behind in filing cybersecurity jobs? As per Rep. Andrew Garbarino, R-N.Y., Chairman of the HHS Cybersecurity and Infrastructure Protection Subcommittee, overseas adversaries have a workforce advantage over FBI cyber personnel of 50 to one. His statements were made during a recent subcommittee hearing titled “Growing the National Cybersecurity Talent Pipeline.” Meanwhile, recent CyberSeek data shows over 650,000 cyber jobs to fill nationwide. Given the rising rate of cyberattacks, these numbers are truly alarming. How…

Will data backups save you from ransomware? Think again

4 min read - Backups are an essential part of any solid anti-ransomware strategy. In fact, research shows that the median recovery cost for ransomware victims that used backups is half the cost incurred by those that paid the ransom. But not all data backup approaches are created equal. A separate report found that in 93% of ransomware incidents, threat actors actively target backup repositories. This results in 75% of victims losing at least some of their backups during the attack, and more than…

Should you worry about state-sponsored attacks? Maybe not.

4 min read - More than ever, state-sponsored cyber threats worry security professionals. In fact, nation-state activity alerts increased against critical infrastructure from 20% to 40% from 2021 to 2022, according to a recent Microsoft Digital Defense Report. With the advent of the hybrid war in Ukraine, nation-state actors are launching increasingly sophisticated attacks. But is this the most prominent danger facing companies today? While nation-state-based attacks cannot be ignored, it looks like insider cyber incidents are far more common. In fact, for the…