Hackers take control of government and business entity accounts on X for crypto scams.

Hackers are increasingly focusing on taking over compromised accounts on X (formerly Twitter), belonging to government and business profiles and bearing 'gold' and 'gray' markings, with the aim of promoting crypto scams, phishing , and crypto drainer sites.
A recent high-profile incident is the account of security firm Mandiant, a subsidiary of Google, on X, which was taken over by hackers yesterday in order to distribute a fake cryptocurrency offering that emptied cryptocurrency wallets. In recent days, it has been reported that the accounts of Canadian senator Amina Gerba, the non-profit consortium 'The Green Grid,' and Brazilian politician Ubiratan Sanderson fell into the hands of hackers.
Yesterday, cybersecurity firm Mandiant's X account was hacked to promote a crypto drainer website. The company says that two-factor authentication was enabled on the account, making the hack even more complicated.
A gold checkmark on an X account indicates an official organization/company, while a gray badge indicates a profile representing a government or official authority. Both types of accounts must meet certain eligibility requirements. In contrast, blue checks are given to any user who pays for an X Premium subscription.
Due to strict eligibility criteria, gold and gray “identity badges” inspire trust, and the content they distribute is usually considered more trustworthy.
See also: Mandiant's X account hacked in crypto scam
While the original idea behind X's verification and subscription payment system is to make counterfeiting and fraud significantly more difficult, gold and gray accounts have become targets for hackers and bargaining chips for cybercriminals.
A recent report from digital risk monitoring platform CloudSEK highlights the emergence of a new black market, where hackers are offering compromised X accounts with gold and gray markings for prices between $1,200 and $2,000. Some sellers are also offering the ability to add scam accounts as partners to verified gold accounts for $500, giving them credibility without the need for more rigorous verification from the social media platform.
See also: PornHub: Blocks access to users in Montana and North Carolina due to age verification laws
Statements from hackers on dark web and Telegram suggest that cybercriminals are also working with compromised inactive corporate accounts that can be converted into “gold” profiles by the buyer. In other cases, hackers who compromise these accounts lock out the legitimate owners, register them for gold for 30 days, and transfer the accounts to the new owners.
CloudSEK reports that it observed six sales of such accounts in one month. One of them, inactive since 2016 and with 28,000 followers, was promoted for $2,500. The researchers recommend that companies close inactive accounts that have been inactive for a long time and check their security settings, enabling two-factor authentication.
Read also: GitHub: Increasingly used for malicious purposes
It is also recommended to check the applications connected to the account as well as the record of active sessions on other devices.
Information source: https://www.bleepingcomputer.com
