- Hackproofing.com
- Posts
- š§ THE MOST SOPHISTICATED PHISHING SCAM YET
š§ THE MOST SOPHISTICATED PHISHING SCAM YET
Personalized, Polished, and Highly DangerousāHere's What You Need to Know
Hiring IT becoming a headache?
IT hiring doesnāt have to be a hassle. Let Crossbridge take care of it allāfrom sourcing top talent to seamless onboarding and more. Get fully vetted resumes in just 24 hours, all handled by real people, not algorithms. Experience the Crossbridge difference.
A new, hyper-targeted phishing attack is making rounds on Xāand itās unlike anything weāve seen before. Guillermo Rauch shares how he almost got tricked by a highly polished fake X support email that perfectly mimicked an actual content violation appeal.
Hereās How the Scam Works:
You receive an email about a "Content Issue" on your X profile.
The email includes your username and looks identical to official HTML emails from X.
Clicking āReview Detailsā redirects you to a fake support site using a sneaky domain (law-x.com instead of law.x.com).
The phishing page includes your profile photo, your real post links, and a convincing āSubmit Appealā flow.
It then asks for your password to proceed.
Once you enter your password, the attacker uses a script to start logging in to X on your behalf.
You then unwittingly hand over the 2FA code, completing the takeover process.
Read Here š
New targeted š hijacking campaign just dropped. This one is more sophisticated than previous attempts š§µ
ā Guillermo Rauch (@rauchg)
1:27 AM ⢠Apr 1, 2025
X Users Say āScams Are Getting Better!!ā š¬
Wow, scammers are definitely getting better at this. We've even seen them use Google AMP in scam texts too:
ā Guardio (@GuardioSecurity)
3:08 PM ⢠Apr 2, 2025
Bypassing Gmail is not easy to begin with, nor is timing the attack to steal both password and 2FA. The email and site are nearly pixel perfect. They probably have a crazy success rate
ā Guillermo Rauch (@rauchg)
7:49 PM ⢠Apr 1, 2025
they're getting too good.
i fear our technically illiterate are long gone when it comes to these scams.
ā Rat the Dog (@RatIsSoCute)
2:09 AM ⢠Apr 1, 2025
Stay sharp, everyone!