惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
博客园_首页
M
MIT News - Artificial intelligence
雷峰网
雷峰网
GbyAI
GbyAI
博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
V
Visual Studio Blog
月光博客
月光博客
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
云风的 BLOG
云风的 BLOG
美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
有赞技术团队
有赞技术团队

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
Ubuntu’s new AI dreams attracted a very old-fashioned cry...
Silviu STAHI · 2026-05-08 · via Consumer Insights

The official Ubuntu account on X (formerly Twitter) was briefly compromised by unknown attackers who used it to promote a fake AI agent and send people to a well-built website where they could share their crypto wallet.

A few days before this incident, Canonical wanted to position Ubuntu as a privacy-friendly, local-first AI platform. Attackers weaponized that exact narrative within days.

A suspected compromise of Ubuntu’s official X account pushed a fake “Ubuntu AI agent” called ‘Numbat,’ directing users to a malicious crypto phishing website designed to steal wallet access.

The attack came shortly after Canonical revealed plans to expand AI integration inside Ubuntu, and after the company was recovering from a prolonged DDoS campaign targeting its infrastructure.

Key takeaways

  • Attackers exploited recent Ubuntu AI announcements to launch a fake crypto campaign
  • A suspected compromise of Ubuntu’s X account helped spread the scam
  • The phishing operation used a fake “Numbat” AI agent tied to Solana
  • The malicious site copied real Ubuntu AI content and branding
  • Users were ultimately pushed toward connecting crypto wallets
  • The campaign arrived shortly after Canonical suffered prolonged DDoS attacks

What really happened

On May 7, users noticed a suspicious thread posted from what appeared to be Ubuntu’s official X account. The posts announced “Numbat,” described as “Ubuntu’s newest AI agent built on Solana.”

At first glance, the announcement seemed plausible. Canonical had already been discussing Ubuntu’s AI direction publicly, and the branding referenced Ubuntu’s “Noble Numbat” naming convention.

Instead of using crude phishing tactics, they built a layered narrative that felt consistent with existing Ubuntu discussions. The X post used professional visuals, authentic branding, and language that closely aligned with Canonical’s previous messaging.

The phishing site operated under the domain “ai-ubuntu[.]com,” which looked enough like an official Canonical subdomain to likely fool distracted users. The attackers also disabled replies on the X thread, making it harder for users to publicly warn others about the scam.

The campaign's real objective emerged only after users interacted with the site. Visitors encountered language suggesting that early participants might qualify for future “$UM” token allocations, accompanied by urgent phrases such as “Snapshot approaching.”

The wording followed a familiar crypto scam formula: create a sense of urgency, imply exclusivity and reward early adopters. When users clicked buttons like “Check eligibility” or “Explore Ubuntu AI,” the site prompted them to connect cryptocurrency wallets.

Attackers likely intended to harvest wallet permissions, steal assets or collect sensitive account information through the approval process.

Were the DDoS attacks connected?

The phishing campaign was launched shortly after Canonical faced a DDoS attack that disrupted Ubuntu infrastructure for nearly five days.

Services including ubuntu.com, Launchpad, and Snap-related systems suffered outages or instability during the incident. According to an It’s Foss report, a group identifying itself as “313 Team” reportedly claimed responsibility for the attacks, although Canonical did not officially confirm attribution.

Canonical had not yet released a detailed public post-incident analysis explaining exactly what happened with the X account, and the post made by the attackers was quickly deleted. The good news is that the DDoS attack has stopped, and all services are up and running.

FAQ


Was Ubuntu launching a crypto AI agent?

Answer: No. The “Numbat” AI project was part of a phishing campaign impersonating Ubuntu and Canonical.


Was Ubuntu’s X account hacked?

Answer: Canonical has not publicly confirmed the exact cause at the time of reporting, but the account appeared to be compromised or abused to spread the scam for a very short time.


What was ai-ubuntu[.]com?

Answer: A fake website designed to mimic Ubuntu AI pages and trick users into connecting crypto wallets.


Was Ubuntu itself compromised?

Answer: No evidence suggested Ubuntu systems or repositories were breached. The incident centered on phishing and web-related attacks.


How can users stay safe?

Answer: Verify domains carefully, avoid connecting wallets to unknown sites and treat AI-themed crypto promotions with skepticism.