Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

551–560 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#551

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

Sounds like the 2005 hack of the Danger Sidekick (early smartphone device). I think the fellow went by the 'nym "ethics".

Dude couldn't exploit it for much, despite being able to takeover/access any account, and everything was in the cloud.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#552

Twitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.

They just disabled tweeting from verified accounts. Right now I have more power than Elon.

can confirm - my wife has a verified account and a company account and both are unable to tweet, though one can still quote retweet apparently, but probably just a lagging feature flag.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#554

Earlier quoted context omitted.

Or a distraction while a bigger hack is going on?

Bingo, they're probably walking away with all of Twitter's internal data as we speak...

Could explain why this happened during business hours. Data flowing out from servers doesn't look out of place then...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#555

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

Nope. They're actually getting away with quite a big loot! The number of unconfirmed transactions has catapulted from ~9k to about ~50k right now, which means there's large amount of activity. It will take a while for the dust to settle. You can watch them here https://www.blockchain.com/btc/unconfirmed-transactions chart https://www.blockchain.com/charts/mempool-count A better graph of the current transactions sitti…

So we're likely talking some 50-100 million of dollars being stolen? Insane.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#556

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

If the hacker regularly does black hat stuff (and perhaps used black hat methods to obtain this access), they risk criminal prosecution by going through the official channel.

Bug bounty programs typically have stringent rules, disqualify many valid reports, and take a long time to pay out. Not surprising to me that they'd cash out in this manner - especially if they got access via a token which expires: they wouldn't have much time to plot on how to monetize the access.

I suspect this was a small operation - a national intelligence organization could have caused orders of magnitude more havoc with this sort of access. Smaller groups don't have the infrastructure to capitalize on such chaos.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#557
post #495
post #452

Earlier quoted context omitted.

Maybe the dude shorted the Twitter stock?

Yeah, I'm not sure there is much to be gained from leaking internal data (are DMs that valuable?). The actual scam is executed so poorly that it can't be the main goal too. "Prooving" you have a good exploit by throwing it away is also not plausible.

Exactly, this would be a pretty reckless way to prove an exploit. You could just tell the potential buyer to create a new account and then tweet from that handle.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#559

Your site is getting hacked, you don't know how the hackers are doing it, what do you do ops wise? Take the whole site down for a few hours? Because the entire platform is compromised, how do you handle that?

More of a b2b context. However, we've had an unannounced pentester achieve RCE on our systems. Not a fun situation.

At that point, we were forced by our contracts, and data protection laws, and a CEO aware of all of these, to shut the affected productive system down. We stopped all services, set the firewalls of our hoster to only accept traffic from our office and that's it, while figuring out wtf happened. Those measures overall reduce the situation to a known situation again. If someone in our office is hostile.. that's another issue.

After a bit of analysis, we figured out the IPs attacking us and we blacklisted those on the firewall of the other production systems. Eventually things cleared up to be a pentest no one told us about.

If the attack had moved into these other systems, we'd have to extend the nuclear solution to those systems too. At that point, we'd have to lockout some 30k+ FTE users. I think we'd be able to make national news with that for our customers. Except.. not good news.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#560

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

But then why set up a rather simply scam instead of getting the bug bounty from twitter? That wallet is currently sitting at about 150k USD and these are rather hard to pay out. Why not just go for 100k USD bug bounty, completely legal and with fame?

They might have expected to get more than 150k USD from the scam.
Post reply on HN