In the age of social media, verification badges hold significant power.
On Twitter, the coveted blue tick (now replaced with “Gold”) signifies legitimacy and influence, commanding increased trust and engagement from followers.
However, with the platform’s recent monetization of verification, a disturbing trend has emerged: CloudSEK unmasks a nefarious scheme: Compromised Twitter Gold accounts for sale on the dark web
Since December 2022, Twitter has offered paid verification through its “Twitter Gold” subscription.
This move opened a loophole for cybercriminals, who exploit various methods to acquire and sell verified accounts on the dark web.
These accounts, advertised on forums and Telegram channels, typically fall into three categories:
Fresh accounts with bought verification: These accounts are newly created and quickly verified through paid subscriptions. They often lack followers and activity, making them ideal for impersonation scams.
Brute-forced existing accounts: Hackers use automated tools to crack passwords and gain access to dormant accounts. Once hijacked, these accounts are verified and sold, offering a seemingly legitimate online persona.
Malware infects devices, stealing login credentials for social media accounts.
Criminals then filter these stolen accounts, identifying and verifying valuable Twitter profiles for resale.
The motivations behind buying Twitter Gold accounts on the dark web are vast:
Organizations and individuals can take proactive steps to protect themselves from Twitter Gold scams:
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…