Crypto journalists on X targeted by scammers posing as them, employing harmful Calendly links in deceptive scheme.
Warnings have been issued by security experts as malicious actors distribute fake clones of the Calendly bot on X, pretending to be crypto journalists. Chinese-speaking victims are being targeted by these con artists who send direct messages with links that imitate the appearance of a legitimate Calendly bot. These links are used for scheduling interviews. However, by granting authorization to the fake clone, victims unknowingly give control of their X account to scammers, who can then distribute phishing links through their posts.
The extent of the scam attack is still unclear, but SlowMist, a blockchain security firm, has noted that the scammers often communicate in broken Chinese and focus on targeting crypto influencers. User @0xcryptowizard on X has stated that the cyber criminals are associated with the crypto hacking group Pink Drainer.
To mitigate the risk of unauthorized access, SlowMist has advised users to delete any suspicious applications or sessions in their X settings.
This is not the first time that scammers have impersonated journalists to exploit victims and steal private data and cryptocurrencies. In November 2023, SlowMist revealed a sophisticated phishing attack on the crypto startup Friend.tech, where fraudsters used fake interviews and malicious scripts to target users. Additionally, during the same month, an unidentified con artist posed as a Forbes journalist and approached holders of Bored Ape Yacht Club NFTs, requesting their experiences with the popular NFT collection. The scammers set up multiple call links and recorded screens using a separate recorder bot during the interviews.
It is important for users to remain vigilant and protect themselves against these types of scams.