Spread – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 04 Sep 2025 05:17:08 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Spread – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Threat actors abuse X’s Grok AI to spread malicious links https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/ https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/#respond Thu, 04 Sep 2025 05:17:08 +0000 https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/

X

Threat actors are using Grok, X’s built-in AI assistant, to bypass link posting restrictions that the platform introduced to reduce malicious advertising.

As discovered by Guardio Labs’ researcher Nati Tal, mavertisers often run sketchy video ads containing adult content baits and avoid including a link to the main body to avoid being blocked by X.

Instead, they hide it in the small “From:” metadata field under the video card, which apparently isn’t scanned by the social media platform for malicious links.

Hiding the malicious link in an ignored field
Hiding the malicious link in an ignored field
Source: @bananahacks

Next, (likely) the same actors ask Grok via a reply to the ad something about the post, like “where is this video from,” or “what is the link to this video.”

Grok parses the hidden “From:” field and replies with the full malicious link in clickable format, allowing users to click it and go straight to the malicious site.

Because Grok is automatically a trusted system account on the X platform, its post boosts the link’s credibility, reach, SEO, and reputation, increasing the likelihood that it will be broadcast to a large number of users.

The researcher has found that many of these links funnel through shady ad networks, leading to scams such as fake CAPTCHA tests, information-stealing malware, and other malicious payloads.

Instead of being blocked by X, they are instead promoted to users on the platform via malicious ads that receive a further boost from Grok.

Tal calls the technique of exploiting this loophole “Grokking,” and notes that it’s very effective, in some cases amplifying malicious ads to reach millions of impressions, as shown below.

Potential solutions include scanning all fields, blocking hidden links, and adding context sanitization to Grok, so the AI assistant does not blindly echo links when asked by users, but instead filters and checks them against blocklists.

Tal confirmed to us that he has contacted X to report the issue and received unofficial confirmation that Grok engineers received the report. 

BleepingComputer has also contacted X to ask if they’re aware of this abuse and whether they plan to do anything about it, but we received no response by publication time.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/feed/ 0 56665
Police Issue Warning on Spread of Fake ‘Fraud Department’ Scammers as One Victim Loses $15,000 to Scheme: Report https://earlybirdsinvest.com/police-issue-warning-on-spread-of-fake-fraud-department-scammers-as-one-victim-loses-15000-to-scheme-report/ https://earlybirdsinvest.com/police-issue-warning-on-spread-of-fake-fraud-department-scammers-as-one-victim-loses-15000-to-scheme-report/#respond Thu, 24 Jul 2025 19:42:28 +0000 https://earlybirdsinvest.com/police-issue-warning-on-spread-of-fake-fraud-department-scammers-as-one-victim-loses-15000-to-scheme-report/

Scammers are reportedly posing as bank fraud investigators to steal money from unsuspecting victims.

According to WPLG Local 10, the Broward Sheriff’s Office (BSO) in Florida has issued a warning about the scheme and is urging the public to be vigilant amid rising cases of bank-related phone scams.

WPLG reports that the BSO Pompano Beach District has already received more than a dozen complaints from residents who were tricked into handing out thousands of dollars to the scammers.

Deputies say that one victim lost $15,000 to the scheme. A couple was also tricked into giving up their debit cards and personal identification numbers (PINs), resulting in more than $9,000 in fraudulent charges.

The bad actors typically contact their prospective victims, pretending to work for the fraud department of the victim’s bank.

The scammers then claim there are suspicious activities on the victim’s account that require immediate action to protect the funds. They then tell the victims to withdraw large sums of money or hand over their debit cards and PINs.

In some cases, the scammer arranges for an Uber to pick up the money or the debit card, instructing the victim to place the envelope containing these items in the backseat and not speak to the driver.

The police say that legitimate banks will not tell their clients to withdraw money and send it through a ride-share service, nor will they ask to hand over debit cards and PINs to a third party.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/police-issue-warning-on-spread-of-fake-fraud-department-scammers-as-one-victim-loses-15000-to-scheme-report/feed/ 0 49457
Fake Crypto Job Interview Used to Spread 'PylangGhost' Malware https://earlybirdsinvest.com/fake-crypto-job-interview-used-to-spread-pylangghost-malware/ https://earlybirdsinvest.com/fake-crypto-job-interview-used-to-spread-pylangghost-malware/#respond Sat, 21 Jun 2025 21:41:05 +0000 https://earlybirdsinvest.com/fake-crypto-job-interview-used-to-spread-pylangghost-malware/

A hacking group tied to North Korea is running a new scam targeting people looking for crypto or blockchain jobs, according to Cisco Talos report on June 18.

The group, known as Famous Chollima (also referred to as Wagemole), has been using fake interviews to spread malware called “PylangGhost”.

This remote access trojan (RAT), built in Python, is based on an older malware strain called GolangGhost.

What is Monero? XMR Animated Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The campaign mainly targets job seekers in India with experience in cryptocurrency. Victims are contacted by fake recruiters posing as representatives of companies, such as Coinbase



$780.2M

, Uniswap



$102.73M

, or Robinhood.

Hackers guide the targets through a fake hiring process, which starts with messages and links to job testing sites that appear genuine. After collecting basic information, they invite candidates to a video call that looks like a real interview.

During the call, they ask the victim to enable camera and microphone access and to run certain computer commands. They claim this is needed to install or update video drivers, but instead, it installs the PylangGhost malware.

Once the malware is active, it gives hackers remote access to the person’s computer. It can collect system information, take screenshots, move files, and stay connected to the machine.

Cisco Talos stated that the malware is used to steal login details from over 80 browser extensions, including MetaMask, Phantom, TronLink, 1Password, NordPass, Bitski, Initia, and MultiverseX. Many of these are used to manage cryptocurrency wallets.

Meanwhile, Mobile Threat Intelligence reported that Crocodilus, an Android malware, has become more dangerous due to recent updates. What can it do? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.

]]>
https://earlybirdsinvest.com/fake-crypto-job-interview-used-to-spread-pylangghost-malware/feed/ 0 43357