A sophisticated financial scam has emerged on X/Twitter, exploiting a critical vulnerability in the platform’s advertising display URL feature.
Cybersecurity researchers have uncovered a campaign that tricks users by displaying trusted domain names in advertisements while redirecting victims to malicious cryptocurrency scam websites.
The attack leverages a known loophole in X/Twitter’s URL handling system, allowing attackers to display one domain to X/Twitter’s crawlers while sending actual visitors to entirely different destinations.
The most recent instance of this attack was discovered on May 1, 2025, when advertisements for a fictitious “Apple iToken” cryptocurrency began appearing on X/Twitter.
What made these ads particularly deceptive was that they showed “From CNN.com” as the display URL, creating a false sense of legitimacy. When users clicked the link, however, they were redirected to cryptocurrency scam websites with elaborate Apple-themed interfaces designed to steal funds.
Silent Push researchers identified this campaign through their threat monitoring systems and determined that the attack represents a significant evolution in social media-based financial scams.
Their investigation revealed that the threat actors behind this campaign have created nearly 90 similar websites dating back to 2024, all featuring almost identical financial lures targeting cryptocurrency investors.
“This attack demonstrates how threat actors continue to find creative ways to abuse legitimate platform features,” noted Silent Push in their report.
The campaign specifically targets users interested in cryptocurrency investments by impersonating Apple and falsely suggesting the company is launching a new digital token. The scam sites even feature fabricated endorsements from Apple CEO Tim Cook to enhance their perceived legitimacy.
The operation’s sophistication is evident in its infrastructure, with researchers identifying 22 different cryptocurrency wallet options for victims to send funds.
Each website in the network maintained unique wallet addresses, complicating tracking and attribution efforts.
The core of this attack exploits how X/Twitter validates and displays URLs in advertisements. As detailed in the Silent Push report, the attackers employ a multi-stage redirection technique that effectively circumvents X/Twitter’s verification systems.
The process begins when attackers submit their advertisement with a URL shortener (such as Bitly) that initially directs to a legitimate website like CNN.com.
When X/Twitter’s crawler follows this link to generate the preview card for the advertisement, it sees the legitimate domain and displays “From CNN.com” in the ad.
However, once the advertisement is approved and published, the attackers modify the URL shortener’s destination to point to their malicious domain.
This creates a complex redirection chain: X/Twitter ad → Bitly shortener → Second X/Twitter URL → Final malicious domain (ipresale.world or similar domains).
In the example documented by Silent Push, the first Bitly URL was created on May 1, 2025, at 19:22 UTC, likely immediately before the advertisement launched.
The redirect chain ultimately led users to domains like “ipresale.world” and “itokensale.live” that mimicked Apple branding while promoting fictional cryptocurrency presales.
This technique was previously reported by Bleeping Computer in March 2024 with similar cryptocurrency scams spoofing other trusted domains like forbes.com, indicating that threat actors continue to successfully exploit this vulnerability despite its public disclosure.
Are you from the SOC and DFIR Teams? – Analyse Real time Malware Incidents with ANY.RUN -> Start Now for Free.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…