Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Account Hijacking. Show all posts

Microsoft X Account Hijacked to Promote Clippy-Themed Crypto Token

 

Microsoft’s account on X was hacked and used to promote a cryptocurrency token, turning the technology company’s 13-million-follower social media presence into part of an apparent crypto pump-and-dump operation. The incident centered on the company’s @Microsoft account and began with activity involving another X profile impersonating Clippy, Microsoft’s former virtual assistant. 

The Microsoft account followed and reposted a post from @clippymsftcto, an account that has since been suspended. The activity subsequently drew attention to a $Clippy token. Another account, @ClippyMSFT, reposted Microsoft’s message and continued promoting the cryptocurrency. That account claimed the token had a liquidity pool directly paired with $MSFT. Microsoft later removed the unauthorized posts and acknowledged that its account had been accessed unauthorized. 

A company spokesperson said the account had been secured and that Microsoft was investigating how the breach occurred. The company also made clear that it had no association with the cryptocurrency which was being promoted. Microsoft said it did not authorize, sponsor or endorse a cryptocurrency associated with Clippy, Microsoft or $MSFT, and had not authorized the use of its branding or intellectual property in connection with such a token. The incident is part of a long pattern of cryptocurrency scams involving compromised accounts belonging to major organizations. 

Microsoft itself experienced a similar breach in June 2024, when its Microsoft India account, which had more than 211,000 followers, was taken. In that case, attackers used the account to impersonate meme-stock trader Keith Gill, known online as Roaring Kitty. They attempted to lure users to a website advertising a supposed GameStop cryptocurrency presale. Victims who connected their wallets and authorized transactions instead had their crypto assets stolen through a wallet-drainer malware. Compromised social media accounts has been a particularly useful tool for cryptocurrency scams, as posts from established organizations can appear more credible to potential victims. 

ScamSniffer reported in December 2023 that approximately $59 million in cryptocurrency has been stolen from 63,000 people through a Twitter advertising campaign using the “MS Drainer” wallet-draining service between March and November. Government accounts have also been targeted. In January 2024, the U.S. Securities and Exchange Commission’s official X account was compromised through a SIM-swapping attack. Attackers used it to publish a fake announcement claiming that Bitcoin exchange-traded funds had received approval, temporarily but significantly moving Bitcoin’s price. 

Eric Council Jr., identified as the hacker who compromised the SEC account, pleaded guilty in February 2025 and was sentenced to 14 months in prison over his involvement in the scheme. Microsoft now has its account secured and the posts associated with the breach removed. Its investigation is ongoing, but the cryptocurrency promotion associated with the unauthorized activity has further raised the risks of trusting what appear to be legitimate social media posts when they involve digital-asset promotions.

One WeChat Call Was Enough to Hijack Accounts Across iPhone and Android

 



A new wave of WeChat vulnerability can turn an incoming voice call into a zero-click account takeover, enabling a compromised account to target another contact without requiring the recipient to answer the call or interact with the device.

Security researchers at Calif developed the exploit and demonstrated its worm-like propagation across an iPhone and two Android devices. In the test, an Android phone called an iPhone and compromised its WeChat account while the incoming call was still ringing. The compromised iPhone then called a second Android phone, allowing the researchers to repeat the takeover.

The attack depends on the caller already being listed as a WeChat contact of the target. Calif said this is not necessarily a strong protection because compromising one account can give an attacker access to that user's trusted contacts, creating opportunities to propagate the attack through existing relationships.

The recipient does not need to answer the call. Calif said answering it also does not prevent exploitation, with the victim hearing nothing while the attack continues. Rejecting the call stops that individual attempt, but an attacker can simply place another call later. This could allow repeated attempts when a target is unavailable, including while the person is asleep.

According to Calif, the vulnerability affects WeChat's VoIP functionality and involves memory corruption. Successful exploitation provides control over the victim's WeChat account, allowing an attacker to read and send messages, make calls and operate the account as its owner. The researchers stressed that the vulnerability by itself does not provide control of the entire smartphone. Chaining it with separate device vulnerabilities could, however, potentially extend an attack beyond the application.

Calif has not released the exploit's technical details and plans to present its full research at a security conference. The company said its researchers used an AI-assisted system designed to explore attack surfaces in messaging applications to identify the vulnerability. Calif said its engineering team identified the bug on July 23, completed an Android exploit on July 30 and demonstrated the worm on August 11. It separately described the initial exploit development as taking about two days, followed by roughly another week to build the worm.

The researchers disclosed the issue to Tencent in July. Tencent subsequently released WeChat 8.0.77 for Android and 8.0.76 for iOS on August 21. Calif said those updates mitigated its exploit and that it confirmed on August 28 that Tencent had also blocked the attack on its servers. On September 4, Calif said Tencent confirmed that the vulnerability could be exploited for remote command execution.

The server-side mitigation means users do not necessarily need to install an update for the specific exploit to be blocked. Keeping the application updated remains advisable, particularly because Tencent has not published a complete list of affected versions. Calif said it tested against Android 8.0.76 and iOS 8.0.75, including iOS 26.6 and older Android releases.

Tencent has not publicly issued a security advisory describing the vulnerability, while its release notes characterize the relevant updates as bug fixes. The company also distributes WeChat clients for HarmonyOS, Windows, macOS and Linux, but Calif has not disclosed whether those versions were tested.

The risk extends beyond private conversations because WeChat incorporates services including payments, official accounts and mini programs. Tencent reported 1.439 billion combined monthly active users for WeChat and Weixin as of June 30, 2026, giving an account-level compromise potential consequences beyond ordinary messaging.

There is currently no indication that the flaw was used in attacks against WeChat users. Calif has not reported an active campaign, and the researchers have not published indicators that defenders could use to identify exploitation. As of September 8, checks also found no CVE identifier for the vulnerability and no corresponding advisory on Tencent's security response site.

The discovery adds to a continuing security concern around zero-click vulnerabilities in communications software. Such attacks can exploit data automatically processed by an application before a user accepts an incoming communication, removing the conventional requirement for a victim to click a malicious link or open an attachment.

Calif's demonstration therefore presents two distinct risks: the immediate compromise of a WeChat account and the possibility of automated propagation through trusted contacts. While Tencent has blocked the demonstrated exploit, the absence of a public technical analysis means users cannot independently determine from the available information whether older or alternative WeChat builds were vulnerable.

Malware Attacks Google-Synced Passkeys

 

Security researchers have uncovered three attack techniques that could allow malware on compromised Windows computers to abuse passkeys synchronized through Google Password Manager. The attacks, collectively called “Pass-ta-key,” target Chrome devices equipped with a Trusted Platform Module (TPM). Rather than breaking the cryptography behind passkeys, the techniques exploit weaknesses in device registration, recovery, user verification, and cloud synchronization. 

Passkeys are widely considered safer than passwords because they cannot be guessed, reused, or easily stolen through phishing. They normally rely on a device-based cryptographic key and may require a PIN, fingerprint, or facial recognition to approve a login. However, Unit 42 researchers found that malware already running on a victim’s computer could manipulate Chrome’s trusted-device mechanisms without requiring administrator privileges or direct user interaction. 

The first technique, Pass-ta-key, abuses Chrome’s TPM-backed device identity key to make Google’s cloud authenticator believe that a request came from the legitimate computer. The service may then return a valid authentication assertion that attackers can use to access a protected account, even without biometric or PIN verification. This attack failed against GitHub because the platform correctly checked the WebAuthn user-verification flag, but it succeeded against eBay before the company fixed the validation issue. 

The second method, Silver Pass-ta-key, enables attackers to register their own verification key during a forced Chrome re-registration process. Malware can invalidate the existing verification state or delete local passkey-related data, allowing the attacker-controlled key to be accepted as proof that the device was unlocked by its owner. The most serious technique, Golden Pass-ta-key, attempts to extract Google Password Manager’s Security Domain Secret from Chrome’s memory. This master key encrypts synchronized passkey records, so stealing it could allow attackers to recover private keys and impersonate the victim from another device. 

Unit 42 said the stolen secret could potentially decrypt both existing and future passkeys because Google’s current implementation reportedly does not provide a method to rotate or revoke it. The findings highlight that passkeys remain resistant to phishing but cannot fully protect accounts when malware controls a trusted device or browser process. Websites should strictly validate user-verification signals, while credential managers should strengthen device enrollment, recovery, re-registration, and protection of encryption keys in memory. Google was notified of the research, although a complete public response or confirmation of remediation was not immediately available.