Attackers gained unauthorized access to Microsoft’s official @Microsoft X account, which has more than 13 million followers, and used it to promote a purported $Clippy cryptocurrency in an apparent pump-and-dump scheme. The account’s profile image was changed to Clippy and it followed and reposted material from @clippymsftcto, an impersonation account that falsely claimed the token’s liquidity pool was tied directly to $MSFT; the impersonator was later suspended.
Microsoft removed the unauthorized content, secured the account, disavowed any cryptocurrency affiliation, and said it is investigating the compromise and will pursue legal action over misuse of its brands and intellectual property. The intrusion method remains unconfirmed; potential avenues cited include phishing, SIM swapping, a compromised recovery email, infostealer-stolen session cookies, or compromised authorized social-media tooling. The incident follows the June 2024 takeover of Microsoft India’s X account, which was used to distribute a cryptocurrency wallet-drainer lure.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
An unauthorized party accessed Microsoft’s @Microsoft X account, which had more than 13 million followers, and changed its profile image to Clippy. The compromised account followed and reposted content from the Clippy-impersonating @clippymsftcto account to amplify a purported $Clippy cryptocurrency token.
Eric Council Jr. pleaded guilty for his role in the conspiracy to compromise the SEC’s X account and manipulate Bitcoin’s value.
Crypto scammers compromised Microsoft India’s @MicrosoftIndia X account, impersonated Keith Gill’s Roaring Kitty persona, and directed users to a purported GameStop crypto-presale site. The site used a wallet drainer to steal assets from users who connected wallets and approved transactions.
Attackers compromised the U.S. Securities and Exchange Commission’s @SECGov account through SIM swapping and posted a false claim that Bitcoin exchange-traded funds had been approved. The post temporarily drove up Bitcoin’s price.
ScamSniffer reported that a Twitter advertising campaign using the MS Drainer wallet drainer stole approximately $59 million in cryptocurrency from 63,000 people between March and November 2023.
Microsoft removed unauthorized posts and secured its official X account after the takeover. It said it has no affiliation with cryptocurrency tokens associated with Clippy, Microsoft, or $MSFT, is investigating the intrusion, and plans legal action over unauthorized use of its brands and intellectual property.
Eric Council Jr. was sentenced to 14 months in prison for his involvement in the conspiracy to compromise the SEC’s X account.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcemkd-cirt.mk
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.