Visualização normal

Antes de ontemStream principal
  • ✇Security | CIO
  • 11 tech experts every CIO should follow on social media
    Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time. Jensen Huang, founder an
     

11 tech experts every CIO should follow on social media

29 de Julho de 2026, 07:00

Social media is more than a place to network or follow the latest headlines and trends. For CIOs, platforms like LinkedIn, X, and Bluesky offer direct access to technology executives, AI experts, economists, and business leaders who share ideas, challenge conventional thinking, and provide insights that can help shape tech strategy. Here, 11 IT leaders share the social media experts they follow, and explain why these voices are worth CIOs’ time.

Jensen Huang, founder and CEO, Nvidia

I find Jensen Huang’s insights (X, LinkedIn) fascinating, and there’s much to be admired and learned from. He’s a bold thinker who fosters a culture of continuous learning, which is incredibly valuable in an ever-evolving tech and cyber business environment like Exos. My observations are that Huang is looking to better the lives of his employees, clients and community — and so am I. His content helps me to think differently and his leadership style has a lot of technical depth, which is especially relevant with the rise and momentum of AI. He’s been described as intensely curious, which aligns with Exos’ tagline, We are Curious. – Jose Martinez, CIO and managing director, Exos IT

Jason Crawford, founder and president, Roots of Progress Institute

Jason Crawford is an under-the-radar voice more CIOs should know. He is one of the most important thinkers on the philosophy and history of technology, and his work is about understanding why technological progress happens and how to sustain it. I follow him because his attention and capital directly drive where the industry moves next. – Yaron Hadad, CEO and CTO, Beehive Software

Kelsey Hightower, distinguished engineer, Google

Kelsey Hightower (Bluesky, LinkedIn) is valuable because he explains cloud infrastructure and Kubernetes in a way that’s practical and grounded. What I appreciate about his work is he often brings the conversation back to simplicity, maintainability, and the people who have to operate these systems. For technology leaders, that matters because the hardest part of cloud adoption isn’t choosing tools but making sure teams can run them reliably over time. – Sai Joshitha Kathari, senior site reliability engineer, Visa

Mustafa Suleyman, CEO, Microsoft AI

As an IT leader and advisor to CIOs, one of the voices I pay the closest attention to is Mustafa Suleyman (X) because he thinks beyond the technology itself. He consistently explores how AI changes institutions, labor markets, governance, and power structures. His work has influenced my own thinking about the growing concentration of AI capability and infrastructure in the hands of a relatively small number of organizations. For CIOs, that perspective is valuable because AI is no longer simply a technology investment, but a strategic, infrastructural, and organizational issue. – Matt Hasan, CEO, aiRESULTS, and founder, The AI Humanist Movement

Kevin Benedict, futurist, Tata Consultancy Services

Over the years, I’ve learned that technology leadership is about following people who help you connect innovation to business results, not the loudest voices. One person I consistently follow and recommend is Kevin Benedict (LinkedIn, X). He consistently delivers insights at the intersection of AI, digital transformation, customer experience, leadership, workforce evolution, and innovation. What distinguishes him is his ability to translate emerging technologies into practical business strategies. Rather than focusing on hype, Benedict focuses on execution, adoption, organizational impact, and measurable outcomes. His insights are practical, strategic, and immediately applicable, making him one of the most valuable voices for CIOs and technology executives navigating today’s rapidly evolving digital landscape. – Paul Bailo, digital transformation executive, educator, author, and founder and CEO, Landit.ai

Ethan Mollick, associate professor, The Wharton School

Ethan Mollick (LinkedIn) has the highest post frequency of the thought leadership I follow. From academic papers to showing model improvements by using his own “otter on a plane writing emails” benchmark, he covers a broad spectrum of AI topics. He frequently gets access to the latest models before they come out, and when they do, his posts give a glimpse of what’s new or different, grounded in longer experience with the products. – Andreas Welsch, founder and chief human agentic AI officer, Intelligence Briefing

Dado Van Peteghem, author and keynote speaker on AI, technology, and business

I suggest Dado Van Peteghem (LinkedIn, TikTok) as a thought leader for CIOs to follow. He provides excellent perspectives on the future of work and offers a strategic guide on how CIOs should adapt to AI, digital ecosystems, and new business models. Van Peteghem helps leadership teams understand how digital transformation goes beyond technology upgrades. His focus is on aligning technology, culture, leadership, and business strategy so digital initiatives create measurable business value rather than becoming isolated IT projects. This aligns with what I advocate, hence my support for him and his idea of digital ecosystems. Van Peteghem spells out how AI changes workflows and how organizations should redesign operating models to decide what should be automated versus what should remain human-driven. – Max Vermeir, VP of AI strategy, ABBYY

David Forino, co-founder and CTO, Quanted

David Forino (LinkedIn), led AI research at Volkswagen’s self-driving team and now often posts on LinkedIn about the data bottleneck in quant finance — how teams spend more time keeping data pipelines running than doing research. It’s the same problem most companies run into when they roll out AI, so his tips are always helpful from someone adjacent to them. – Charlie Simionescu-Marin, co-founder and CEO, Quanted

Justina Nixon-Saintil, chief impact officer and president, IBM International Foundation

I have a unique perspective on Justina Nixon-Saintil (LinkedIn) because I’ve also benefited from her guidance and mentorship through Salynt. What stands out to me is her focus on responsible innovation, workforce transformation, and AI governance. She talks about the people and the organizational side of technology adoption, which is often overlooked. Her perspective has reinforced for me that successful AI adoption is as much about trust, culture, and change management as it is about the technology itself. – Natalia Crosdale, COO, Salynt and a former US State Department technology program leader.

Niall Ferguson, senior fellow, The Hoover Institution, Stanford University

Fundamentally, I get the most value from the big brains who focus on consequences rather than capabilities. They help inspire my own thinking about which assumptions about my business stop being true because transformative technology exists. One of the most important voices I follow is Niall Ferguson (LinkedIn, X). He’s a historian, not a technologist, which is precisely why he’s valuable. Technology changes quickly. Institutions, markets, and power structures change slowly. Understanding the gap between the two is where many of the biggest opportunities and risks emerge. – Bill Huber, partner, digital platforms and solutions, ISG

Erik Bernhardsson, CEO, Modal

Good sources don’t make decisions for me, but they improve the quality of questions I ask before I make them. Erik Bernhardsson (LinkedIn) is at the intersection of AI, data infrastructure, and developer experience. Coming from Spotify and now building Modal, he brings a practical view of what modern AI infrastructure actually requires: fast iteration, flexible compute, and reducing infrastructure friction for teams. – Piotr Mynarski, technology director, eSky.com

  • ✇Blog oficial da Kaspersky
  • XChat de Elon Musk: o novo aplicativo de mensagens é seguro? | Blog oficial da Kaspersky Alanna Titterington
    Pavel Durov e seu aplicativo de mensagens “privadas” têm um novo rival: ninguém menos do que Elon Musk e seu XChat. Explicamos várias vezes no nosso blog que as alegações de Durov sobre a privacidade e a segurança do Telegram são exageradas, para dizer o mínimo. Aqui, vou apenas lembrar ao leitor que as conversas padrão (não secretas) no Telegram não são protegidas por criptografia de ponta a ponta, que é o requisito mínimo para que os dados do usuário permaneçam privados. Mas voltemos a Musk. N
     

XChat de Elon Musk: o novo aplicativo de mensagens é seguro? | Blog oficial da Kaspersky

24 de Junho de 2026, 10:00

Pavel Durov e seu aplicativo de mensagens “privadas” têm um novo rival: ninguém menos do que Elon Musk e seu XChat. Explicamos várias vezes no nosso blog que as alegações de Durov sobre a privacidade e a segurança do Telegram são exageradas, para dizer o mínimo. Aqui, vou apenas lembrar ao leitor que as conversas padrão (não secretas) no Telegram não são protegidas por criptografia de ponta a ponta, que é o requisito mínimo para que os dados do usuário permaneçam privados.

Mas voltemos a Musk. No final de abril de 2026, o aplicativo XChat foi lançado para usuários do iOS. O magnata da tecnologia vinha exaltando as qualidades do seu aplicativo de mensagens há muito tempo, alegando desde o início que se tratava de uma maneira incrivelmente privada e segura de se comunicar, representando uma ameaça direta ao Signal, WhatsApp, Telegram e iMessage. Hoje, analisamos se é prudente confiar nas <s>promessas de Musk</s> em relação a este novo serviço, detalhamos seus principais recursos e o comparamos à concorrência.

Criptografia no estilo Bitcoin

Musk falou sobre o XChat pela primeira vez em 1º de junho de 2025, naturalmente por meio da sua conta no X (o antigo Twitter). Quando um usuário perguntou quando o novo serviço seria lançado, Musk respondeu: “Essa semana, se não houver problemas de escalabilidade”.

Aparentemente, havia problemas de escalabilidade: a versão beta do aplicativo só foi lançada em setembro de 2025 e os usuários do iOS só obtiveram acesso total ao serviço em abril de 2026. Até o momento da publicação deste artigo, não havia informações sobre quando essa versão será lançada para o Android. Apesar disso, uma página do XChat já está ativa no Google Play, onde os usuários podem <s>enfileirar-se</s> para fazer um “pré-registro”, o que quer que isso signifique.

Mas, vamos voltar à postagem de Musk anunciando o XChat. Essa postagem específica chamou a atenção da comunidade de especialistas em privacidade e cibersegurança, e aqui está o motivo: o magnata da tecnologia informou que o serviço seria construído em uma “arquitetura totalmente nova” e apresentaria “criptografia no estilo Bitcoin”, além de ser escrito em Rust.

O anúncio de Elon Musk sobre o XChat

Elon Musk anuncia o lançamento do XChat, alegando que o novo aplicativo de mensagens é escrito em Rust e usa “criptografia no estilo Bitcoin”. Fonte

A comunidade de especialistas passou muito tempo tentando descobrir o que Musk quis dizer com isso. Afinal, o Bitcoin não é um sistema criptografado e anônimo de troca de dados. A blockchain utiliza chaves criptográficas públicas e privadas, mas para um propósito totalmente distinto: a assinatura de transações. Além disso, essas transações não estão escondidas de olhares indiscretos; elas estão disponíveis para qualquer um ver, para sempre. Simplificando: a fim de proteger os seus usuários, o Bitcoin não garante a privacidade deles, mas faz exatamente o oposto, ou seja, oferece transparência máxima.

É provável que Musk tenha usado a “criptografia no estilo Bitcoin” como uma estratégia de marketing. Na época do anúncio, o Bitcoin estava sendo negociado próximo de suas máximas históricas, e as criptomoedas dominavam as conversas. Tecnicamente, a versão beta do XChat, lançada em setembro de 2025, protegia as conversas dos usuários com um “tipo” de criptografia de ponta a ponta, mas isso foi implementado de uma forma que levantou sérias dúvidas entre os especialistas em criptografia.

E não sem uma razão. Normalmente, ao configurar um chat com criptografia de ponta a ponta, é gerado automaticamente um par de chaves criptográficas: uma pública e uma privada. A chave pública é usada para criptografar mensagens, enquanto a chave privada as descriptografa. Como outros usuários precisam da sua chave pública para iniciar uma conversa segura com você, essas chaves geralmente são armazenadas nos servidores do aplicativo.

A chave privada, no entanto, deveria ser armazenada somente no dispositivo do usuário, que é exatamente o que o Signal faz. Isso serve como uma garantia simples e firme de que nem a própria empresa nem qualquer terceiro que viole a infraestrutura dela possa acessar as conversas dos usuários, mesmo que realmente desejem.

Mas os projetos de Elon Musk seguem uma cartilha própria: os desenvolvedores do XChat decidiram que seria uma ótima ideia armazenar as chaves privadas dos usuários nos servidores do XChat. O X afirma que utilizará módulos de segurança de hardware (HSMs) para armazenar essas chaves privadas, dispositivos especializados projetados para impedir que até mesmo o proprietário do sistema tenha acesso fácil aos dados armazenados nele. No entanto, os especialistas também estão questionando a confiabilidade dessa configuração, e chegaram a uma conclusão sombria: se o X realmente quiser obter a chave privada de um usuário, é provável que consiga.

Entenda como as mensagens criptografadas do XChat funcionam na prática

Depois que os problemas de escalabilidade foram resolvidos quase um ano após o anúncio de Musk, o X lançou oficialmente o aplicativo XChat para iOS em abril de 2026. Agora, qualquer pessoa pode usá-lo. Mas do ponto de vista prático, a situação envolvendo conversas criptografadas parece ainda mais complicada do que no Telegram.

De acordo com a Central de Ajuda da rede social, para usar a criptografia de conversas de ponta a ponta no XChat, ambos os usuários devem ter uma conta no X e configurar o XChat. Além disso, deve haver algum tipo de conexão entre eles:

  • Seguir um ao outro ou estar inscrito na conta um do outro
  • Ter trocado mensagens anteriormente
  • Ter aceito uma solicitação de mensagem direta
  • Ser membros da mesma assinatura Premium Business/Premium Organization no X

Se os usuários não seguem um ao outro e não interagiram antes, pode ser que o XChat ainda permita que eles enviem uma solicitação de mensagem. No entanto, essa solicitação inicial não estará abrangida pela criptografia de ponta a ponta.

Pelo menos é assim que o processo é descrito na documentação da ajuda oficial do aplicativo de mensagens. Parece complicado demais? Não se preocupe: isso funciona de forma completamente diferente na prática. Ou melhor, não funciona. Eu consegui enviar uma mensagem para outro usuário que NÃO havia configurado o XChat. O aplicativo em si, é claro, não me avisou sobre isso.

O XChat permite que os usuários enviem mensagens para pessoas que não configuraram o aplicativo

O aplicativo permite iniciar uma conversa com um usuário que ainda nem configurou o XChat, sem qualquer aviso.

A história fica ainda melhor. O usuário para o qual eu enviei uma mensagem recebeu uma notificação na versão da Web do X, mas não conseguiu acessar a mensagem. Aqui está o motivo: antes de usar o XChat, é necessário criar um PIN de quatro dígitos. No entanto, o PIN é solicitado na primeira vez que o usuário tenta acessar o aplicativo, ou seja, antes mesmo dele ter a chance de criar um PIN. Além disso, o usuário recebe um aviso de que, sem o PIN, não será possível visualizar conversas anteriores criptografadas.

O XChat solicita um PIN antes mesmo do usuário criar um

O usuário deve inserir um PIN para descriptografar mensagens anteriores antes mesmo de concluir a configuração inicial do XChat.

A única solução que encontrei para poder usar o XChat foi tocar em “Esqueceu o PIN?” (ainda que esse PIN nunca tenha existido), confirmar a minha identidade e criar um novo PIN (ou melhor, o primeiro). Conforme já mencionado, isso faz com que você perca o acesso ao histórico de conversas, não podendo ler nenhuma mensagem enviada a você no XChat antes de ter configurado oficialmente o aplicativo.

XChat: o novo Telegram, WhatsApp, Signal… ou talvez o novo Facebook Messenger?

Todos esses obstáculos com relação ao PIN existem por um motivo. Lembre-se, ao contrário do WhatsApp e do Signal, os desenvolvedores do XChat decidiram armazenar as chaves privadas dos usuários no próprio servidor do aplicativo. Sendo assim, o aplicativo usa esses PINs de quatro dígitos para criptografar essas chaves.

De acordo com a documentação da ajuda do XChat, esse mecanismo foi projetado para garantir a integração “perfeita” entre vários dispositivos. É difícil ignorar o fato de que WhatsApp e Signal resolveram esse problema sem recorrer a artifícios questionáveis, como requisitos de PIN ou o armazenamento de chaves privadas em servidores.

O problema é que soluções alternativas como essas invalidam qualquer alegação de privacidade e segurança do aplicativo. Um PIN (a principal solução alternativa adotada) não é considerado a maneira mais segura de proteger dados confidenciais. Mencionamos várias vezes que combinações de quatro dígitos são fáceis de decifrar usando técnicas de força bruta, especialmente porque o XChat oferece 20 tentativas generosas para inserir o código certo.

O XChat avisa sobre o bloqueio após 20 tentativas malsucedidas

O aplicativo permite até 20 tentativas para inserir o PIN de quatro dígitos. Após o limite ser atingido, o XChat avisa que o acesso às mensagens será perdido permanentemente.

Como se não bastasse a implementação confusa de criptografia de ponta a ponta quando comparada à de outros aplicativos, a impressão geral é de que não faz sentido usar o XChat. Um jornalista da Wired fez um comentário certeiro: o aplicativo se parece mais com o Facebook Messenger do que com o WhatsApp, Signal ou Telegram. Mas enquanto as pessoas geralmente abrem o Messenger para ler mensagens enviadas pela mãe ou pela avó, o XChat parece destinado a três tipos de pessoas: as que querem investigar o seu sobrinho estranho que passa todo o tempo livre no X, as que ainda acreditam na promessa de US$ 500 mil em Bitcoin feita por John McAfee e fãs de Elon Musk.

Então, qual é a conclusão sobre o XChat?

A melhor maneira de encerrar esta postagem é com uma citação de um especialista em cibersegurança: “Se o que você busca é segurança, use o Signal. Se o que você quer é falar com praticamente qualquer pessoa usando mensagens criptografadas, use o WhatsApp. Se toda a sua vida gira em torno do X, suponho que isso seja melhor do que nada.”

Se você usar o XChat, a regra número um é não criar um PIN previsível: jamais use o ano do seu nascimento ou, pior, a sequência 1234. Também é importante não esquecer esse código, porque se isso acontecer, todo o seu histórico de conversas desaparecerá para sempre. Por fim, assim como acontece com suas outras senhas, você não deve armazená-la no aplicativo de notas, mas sim em um gerenciador de senhas seguro. Isso não apenas evitará que você tenha de memorizar dezenas de combinações de caracteres, como também reduzirá o risco de perder o acesso a dados e conversas importantes.

Para saber mais sobre mensagens seguras em outros aplicativos, confira nossas outras postagens:

Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches

A hacker is selling a 340M OnlyFans user database allegedly built by matching old breach data and public profiles to real OnlyFans accounts.

X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams

Executive Summary

  • An active phishing campaign is targeting high-profile X accounts in an attempt to hijack and exploit them for fraudulent activity.
  • This campaign has been observed targeting a variety of individual and organization accounts such as U.S. political figures, leading international journalists, an X employee, large technology organizations, cryptocurrency organizations, and owners of valuable, short usernames.
  • SentinelLABS’ analysis links this activity to a similar operation from last year that successfully compromised multiple accounts to spread scam content with financial objectives. While the activity detailed here is centered around X/Twitter accounts, this actor is not limited to a single social platform, and can be observed directing attention to other popular services as well, while seemingly pursuing the same financial objectives.

If you’ve encountered similar suspicious activity, SentinelLABS would love to hear from you — please reach out to the team at ThreatTips@sentinelone.com.

Account Compromise Process

Thanks to tips from targets and collaboration with industry partners, SentinelLABS has observed a variety of phishing lures tied to this campaign over the past few weeks. One example is the classic account login notice. The links in the email received by the target are not legitimate and lead to credential phishing sites. Other observed lures use copyright violation themes. However, SentinelLABS notes that directly phishing users may not be the only access method employed by this attacker.

An X ‘new login’-themed phishing email

In recent cases, we observed the actor abusing Google’s “AMP Cache” domain cdn.ampproject[.]org to evade email detections and redirect the user to a phishing domain:

https://cdn.ampproject[.]org/c/s/x-recoverysupport.com/reset/?username=[X-USERNAME]

This ultimately leads the targets to an actor-made phishing website seeking X account credentials:

X credential phishing page

In the copyright infringement lure scenario, the user will first visit an Action Needed page before being prompted to enter credentials:

X fake copyright infringement page

Once an account is taken over, the attacker swiftly locks out the legitimate owner and begins posting fraudulent cryptocurrency opportunities or links to external sites designed to lure additional targets, often with a crypto theft-related theme. Ultimately, compromising high-profile accounts enables the attacker to reach a broader audience of potential secondary victims, maximizing their financial gains.

Widespread Activity

In recent activity associated with this campaign, the domain securelogins-x[.]com has been used to deliver emails and x-recoverysupport[.]com to host phishing pages. Our observations indicate a level of informality and flexibility of infrastructure use – meaning any of these domains can be considered email delivery or phishing page hosting.

An overall collection of recent activity can be observed hosted on 84.38.130[.]20, an IP associated with a Belize-based VPS service called Dataclub. The domains themselves have been predominantly registered through Turkish hosting provider Turkticaret.

Inspecting the DNS history of 84.38.130[.]20 leads to a variety of interestingly related domains. As shown below, the cluster of activity began in mid-2024 and continues today. While this is only one phishing page hosting IP, it provides a good perspective of the length of this activity and its ability to avoid much attention for over a year.

Validin Infrastructure Analysis Timeline

Our observations suggest that the attacker is highly adaptable, continuously exploring new techniques while maintaining a clear financial motive. The targeting appears constrained, yet opportunistic. Notably, past public reports have attributed related activity to Turkish-speaking actors based on language phishing page source comment language. At this time, we do not attribute this campaign to a specific country or any widely-tracked threat actor.

Some of the malicious sites and content hosted across 84.38.130[.]20 are built using the FASTPANEL DIRECT service.

FASTPANEL landing page on buy-tanai[.]com

FASTPANEL is a website hosting and building service that specializes in rapid building and management of websites. While FASTPANEL is not a malicious service, it is frequently abused by bad actors due to the ease of use, rapid scalability, and relatively low cost. FASTPANEL is routinely utilized by drainer gains and phishing campaigns, and is also included in associated guides and tutorials distributed throughout cybercrime communication channels.

Example discussion of FASTPANEL (RU crime forum)

Of the sites hosted on 84.38.130[.]20, the buy-tanai[.]com and emotionai[.]live sites still present the FASTPANEL landing pages as of this writing.

Publicly Linkable Activity

Emerging Account Intrusions

While we have not yet established a high-confidence link, a recent compromise of a Tor Project account closely mirrors our observations. On January 30, 2025, the official X account for the Tor Project was breached. While it is possible that the same threat actor is responsible, we lack sufficient evidence to confirm the connection as of this writing.

X post from The Tor Project account on January 30, 2025 advising users of a potential compromise
Tor Project account compromise notice

The Decentralized Autonomous Wireless Network (DAWN) was another victim of this type of attack. The threat actor leveraged the compromised DAWN-related social media accounts to lure victims into entering credentials into phishing pages targeting X and Telegram credentials.

DAWN X Posts

The compromise of DAWN’s X accounts goes back to mid-January 2025.

January 14, 2025 – DAWN rewards compromise post

Crypto-Themed Project Placeholders

In some cases, we’ve observed cryptocurrency themed projects seemingly acting as placeholders for future use, or direct pump-and-dump schemes. In one example, buy-tanai[.]com was pitched as such: “$TANA AI. Dawn’s AI project, Tana is the first AI-powered LP and trading agent, now live on the Solana blockchain.”

Tana AI (TANA) on Pump[.]fun

The domainbuy-tanai[.]com currently displays default FASTPANEL landing pages, suggesting it — along with other similar domains — is being staged for future attacks. Since FASTPANEL-managed sites can be rapidly updated, these domains serve as adaptable templates for phishing campaigns.

Notably, TANA AI (TANA) was launched by Dawn in mid-January to promote AI-driven trading and liquidity provision in the cryptocurrency market. Despite losing most of its initial value within days, the currency remains actively traded across multiple decentralized exchanges.

Given the crypto-related nature of these domains, it is likely that threat actors are using them as flexible phishing infrastructure. By keeping them as blank templates, they can quickly modify hosted content to align with ongoing campaigns as needed.

Crimeware Relations

Several other domains share overlaps in both use and unique infrastructure details, yet they represent a fork from the previously described high-profile social media profile attacks, including:

  • dataoptimix[.]com
  • gamecodestudios[.]com
  • shortwayscooter[.]com

The domain shortwayscooter[.]com hosts fake captchas that deliver the DanaBot banking trojan. DataOptimix is branded as a generative AI solution, though there are few details about what the service does.

DataOptimix

Historical Connections

In mid-2024, a campaign used related infrastructure in similar phishing messages, including those which compromised the Linus Tech Tips Twitter account along with several other high profile users. At the time, @LinusTech had roughly 1.8million followers, which may represent the highest profile account successfully hijacked and linked to this actor.

Linus Tech Tips Twitter compromise

Conclusion

The cryptocurrency landscape offers financially-motivated threat actors multiple opportunities for profit and fraud. While marketing for coins and tokens has long been irreverent and meme-driven, recent developments have further blurred the line between legitimate projects and scams.

A striking example occurred in January 2025, when the X account of the late crypto-enthusiast and antivirus founder John McAfee was reactivated to promote a new coin, $AIntivirus. The marketing style and brand voice of this purportedly legitimate token closely resemble tactics used in known scam campaigns, highlighting how easily crypto enthusiasts can be misled in an already murky ecosystem.

To safeguard your X account, we strongly recommend using a unique password, enabling two-factor authentication (2FA), and avoiding credential sharing with third-party services. Be especially cautious of messages containing links to account alerts or security notices. Always verify URLs before clicking, and if a password reset is needed, initiate it directly through the official website or app rather than relying on unsolicited links.

If you’ve encountered similar suspicious activity, we’d love to hear from you. Contact SentinelLABS at ThreatTips@sentinelone.com.

Indicators of Compromise

Domains
buy-tanai[.]com
dataoptimix[.]com
gamecodestudios[.]com
infringe-x[.]com
protection-x[.]com
rewards-dawn[.]com
securelogins-x[.]xyz
shortwayscooter[.]com
violationappeal-x[.]com
violationcenter-x[.]com
x-accountcenter[.]com
x-changealerts[.]com
x-logincheck[.]com
x-loginhelp[.]com
x-passwordrecovery[.]com
x-recoveraccount[.]com
x-suspiciouslogin[.]com

SHA-1
e2221e5c58a1a976e59fe1062c6db36d4951b81e – PHP file containing URL associated with X credential phishing activity

❌
❌