Cyber Security News

New Attack Exploiting X/Twitter Advertising Display URL Feature to Trick Users

A sophisticated financial scam has emerged on X/Twitter, exploiting a critical vulnerability in the platform’s advertising display URL feature.

Cybersecurity researchers have uncovered a campaign that tricks users by displaying trusted domain names in advertisements while redirecting victims to malicious cryptocurrency scam websites.

The attack leverages a known loophole in X/Twitter’s URL handling system, allowing attackers to display one domain to X/Twitter’s crawlers while sending actual visitors to entirely different destinations.

The most recent instance of this attack was discovered on May 1, 2025, when advertisements for a fictitious “Apple iToken” cryptocurrency began appearing on X/Twitter.

What made these ads particularly deceptive was that they showed “From CNN.com” as the display URL, creating a false sense of legitimacy. When users clicked the link, however, they were redirected to cryptocurrency scam websites with elaborate Apple-themed interfaces designed to steal funds.

Ad abusing the Apple brand, fake “iToken” product, and spoofing the landing page URL to show “From CNN[.]com” (Source – Silent Push)

Silent Push researchers identified this campaign through their threat monitoring systems and determined that the attack represents a significant evolution in social media-based financial scams.

Their investigation revealed that the threat actors behind this campaign have created nearly 90 similar websites dating back to 2024, all featuring almost identical financial lures targeting cryptocurrency investors.

“This attack demonstrates how threat actors continue to find creative ways to abuse legitimate platform features,” noted Silent Push in their report.

The campaign specifically targets users interested in cryptocurrency investments by impersonating Apple and falsely suggesting the company is launching a new digital token. The scam sites even feature fabricated endorsements from Apple CEO Tim Cook to enhance their perceived legitimacy.

The operation’s sophistication is evident in its infrastructure, with researchers identifying 22 different cryptocurrency wallet options for victims to send funds.

Each website in the network maintained unique wallet addresses, complicating tracking and attribution efforts.

Technical Analysis of the URL Spoofing Mechanism

The core of this attack exploits how X/Twitter validates and displays URLs in advertisements. As detailed in the Silent Push report, the attackers employ a multi-stage redirection technique that effectively circumvents X/Twitter’s verification systems.

The process begins when attackers submit their advertisement with a URL shortener (such as Bitly) that initially directs to a legitimate website like CNN.com.

When X/Twitter’s crawler follows this link to generate the preview card for the advertisement, it sees the legitimate domain and displays “From CNN.com” in the ad.

However, once the advertisement is approved and published, the attackers modify the URL shortener’s destination to point to their malicious domain.

ipresale[.]world (Source – Silent Push)

This creates a complex redirection chain: X/Twitter ad → Bitly shortener → Second X/Twitter URL → Final malicious domain (ipresale.world or similar domains).

In the example documented by Silent Push, the first Bitly URL was created on May 1, 2025, at 19:22 UTC, likely immediately before the advertisement launched.

The redirect chain ultimately led users to domains like “ipresale.world” and “itokensale.live” that mimicked Apple branding while promoting fictional cryptocurrency presales.

This technique was previously reported by Bleeping Computer in March 2024 with similar cryptocurrency scams spoofing other trusted domains like forbes.com, indicating that threat actors continue to successfully exploit this vulnerability despite its public disclosure.

Are you from the SOC and DFIR Teams? – Analyse Real time Malware Incidents with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago