actors – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 04 Sep 2025 05:17:08 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 actors – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Threat actors abuse X’s Grok AI to spread malicious links https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/ https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/#respond Thu, 04 Sep 2025 05:17:08 +0000 https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/

X

Threat actors are using Grok, X’s built-in AI assistant, to bypass link posting restrictions that the platform introduced to reduce malicious advertising.

As discovered by Guardio Labs’ researcher Nati Tal, mavertisers often run sketchy video ads containing adult content baits and avoid including a link to the main body to avoid being blocked by X.

Instead, they hide it in the small “From:” metadata field under the video card, which apparently isn’t scanned by the social media platform for malicious links.

Hiding the malicious link in an ignored field
Hiding the malicious link in an ignored field
Source: @bananahacks

Next, (likely) the same actors ask Grok via a reply to the ad something about the post, like “where is this video from,” or “what is the link to this video.”

Grok parses the hidden “From:” field and replies with the full malicious link in clickable format, allowing users to click it and go straight to the malicious site.

Because Grok is automatically a trusted system account on the X platform, its post boosts the link’s credibility, reach, SEO, and reputation, increasing the likelihood that it will be broadcast to a large number of users.

The researcher has found that many of these links funnel through shady ad networks, leading to scams such as fake CAPTCHA tests, information-stealing malware, and other malicious payloads.

Instead of being blocked by X, they are instead promoted to users on the platform via malicious ads that receive a further boost from Grok.

Tal calls the technique of exploiting this loophole “Grokking,” and notes that it’s very effective, in some cases amplifying malicious ads to reach millions of impressions, as shown below.

Potential solutions include scanning all fields, blocking hidden links, and adding context sanitization to Grok, so the AI assistant does not blindly echo links when asked by users, but instead filters and checks them against blocklists.

Tal confirmed to us that he has contacted X to report the issue and received unofficial confirmation that Grok engineers received the report. 

BleepingComputer has also contacted X to ask if they’re aware of this abuse and whether they plan to do anything about it, but we received no response by publication time.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/feed/ 0 56665
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/ https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/#respond Sun, 20 Jul 2025 14:36:11 +0000 https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/

Hacker

A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals.

The PoisonSeed threat actors are known to employ large-volume phishing attacks for financial fraud. In the past, distributing emails containing crypto seed phrases used to drain cryptocurrency wallets.

In the recent phishing attack observed by Expel, the PoisonSeed threat actors do not exploit a flaw in FIDO2’s security but rather abuse the legitimate cross-device authentication feature.

Cross-device authentication is a WebAuthn feature that allows users to sign in on one device using a security key or authentication app on another device. Instead of requiring a physical connection, such as plugging in a security key, the authentication request is transmitted between devices via Bluetooth or a QR code scan.

The attack begins by directing users to a phishing site that impersonates corporate login portals, such as from Okta or Microsoft 365.

When the user enters their credentials into the portal, the campaign uses an adversary-in-the-middle (AiTM) backend to silently log in with the submitted credentials on the legitimate login portal in real-time.

The user targeted in the attack normally would use their FIDO2 security keys to verify multi-factor authentication requests. However, the phishing backend instead tells the legitimate login portal to authenticate using cross-device authentication.

This causes the legitimate portal to generate a QR code, which is transmitted back to the phishing page and displayed to the user.

When the user scans this QR code using their smartphone or authentication app, it approves the login attempt initiated by the attacker.

PoisonSeed attack flow to bypass FIDO2 protections
PoisonSeed attack flow to bypass FIDO2 protections
Source: Expel

This method effectively bypasses FIDO2 security key protections by allowing attackers to initiate a login flow that relies on cross-device authentication instead of the user’s physical FIDO2 key.

Expel warns that this attack does not exploit a flaw in the FIDO2 implementation, but instead abuses a legitimate feature that downgrades the FIDO key authentication process.

To mitigate the risk, Expel recommends the following defenses:

  • Limiting geographic locations from which users are allowed to log in and establishing a registration process for individuals traveling.
  • Routinely check for the registration of unknown FIDO keys from unknown locations and uncommon security key brands.
  • Organizations can consider enforcing Bluetooth-based authentication as a requirement for cross-device authentication, which significantly reduces the effectiveness of remote phishing attacks.

Expel also observed a separate incident where a threat actor registered their own FIDO key after compromising an account via what is believed to be phishing and resetting the password. However, this attack did not require any methods to trick the user, like a QR code.

This attack highlights how threat actors are finding ways to bypass phishing-resistant authentication by tricking users into completing login flows that bypass the need for physical interaction with a security key.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/feed/ 0 48711
Threat actors abuse Google Apps Script in evasive phishing attacks https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/ https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/#respond Thu, 29 May 2025 16:33:23 +0000 https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/

Threat actors abuse Google Apps Script in evasive phishing attacks

Threat actors are abusing the ‘Google Apps Script’ development platform to host phishing pages that appear legitimate and steal login credentials.

This new trend was spotted by security researchers at Cofense, who warn that the fraudulent login window is “carefully designed to look like a legitimate login screen.”

“The attack uses an email masquerading as an invoice, containing a link to a webpage that uses Google Apps Script, a development platform integrated across Google’s suite of products,” Cofense explains.

“By hosting the phishing page within Google’s trusted environment, attackers create an illusion of authenticity. This makes it easier to trick recipients into handing over sensitive information.”

Legitimate service abuse

Google Apps Script is a JavaScript-based cloud scripting platform from Google that allows users to automate tasks and extend the functionality of Google Workspace products like Google Sheets, Docs, Drive, Gmail, and Calendar.

These scripts run on a trusted Google domain under “script.google.com,” which is on the allowlist of most security products.

Attackers write a Google Apps Script that displays a fake login page to capture the credentials victims enter. The data is exfiltrated to the attacker’s server via a hidden request.

Phishing page hosted on Google infrastructure
Phishing page hosted on Google infrastructure
Source: Cofense

As the platform allows anyone with an account to publish a script as a public web app, giving it a Google domain, the threat actors can easily share it with the victims via a phishing email that won’t trigger any warnings.

The phishing email contains an invoice payment or tax-related call to action for the recipient, linking to the malicious Google-hosted phishing page.

Sample of a phishing email used in the attacks
Sample of a phishing email used in the attacks
Source: Cofense

After the victim enters their username and password, they are redirected to the legitimate service that was spoofed to lower suspicion and give threat actors time to exploit the stolen data.

Google Apps Script appears to be the new focus of phishing actors that look for legitimate platforms to abuse for evasion and operational efficiency.

In this case, it also gives the attackers the flexibility to remotely adjust their script without having to resend a new link, switching to a different lure without much effort.

An effective defense measure would be to configure email security to scrutinize cloud service links and, if possible, block access to Google Apps Script URLs altogether, or at least flag them as potentially dangerous.

BleepingComputer has contacted Google to ask if they plan to implement any anti-abuse measures in response to Cofense’s findings, but we have not heard back as of publication.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/feed/ 0 38994