Malicious cryptocurrency scheme targets Android and iOS users



Researchers have discovered a sophisticated malicious cryptocurrency scheme that targets mobile devices running Android or iOS.

Malicious apps are distributed through fake websites and imitate legitimate wallet services such as MetaMask, Coinbase, Trust Wallet, TokenPocket, BitPay, ImToken and OneKey. Fake websites are promoted with advertisements on legitimate sites by using deceptive articles.

Researchers say threatening actors are also recruiting middlemen through Telegram and Facebook groups to help distribute the malicious scheme. ESET Research says that the primary target of malicious apps is to steal users’ funds and recently, the scheme has largely targeted Chinese users. As cryptocurrencies gain popularity, ESET expects the technology to spread to other markets.

“Starting in May 2021, our research uncovered dozens of Trojanized cryptocurrency wallet apps,” says ESET researcher Lukas Otefanko.



“It is a sophisticated attack vector because the author of the malware has done a thorough analysis of the legitimate applications abused in this scheme, allowing their malicious code to be inserted in places where it would be difficult to detect, as well as to ensure Do that as such have been crafted. The apps had the same functionality as the original. At this point, ESET Research believes this is likely the work of a criminal group.”

He says malicious apps also represent another threat, as some of them send secret prey seed phrases to attackers’ servers using unsecured HTTP connections. This means that the victim’s funds can be stolen both by the operator of the scheme and by a different attacker on the same network.

“We also discovered 13 malicious apps impersonating the Jaxx Liberty Wallet. These apps were available on the Google Play Store,” tefanko says.

On Telegram, a free and popular multi-platform messaging app with advanced privacy and encryption features, ESET found dozens of groups promoting malicious copies of a cryptocurrency mobile wallet. The research company assumes that these groups were created by the threat actor behind the plan in search of further distribution partners. ESET says this activity has continued through May 2021.

“As of October 2021, we found that these Telegram groups were shared and promoted in at least 56 Facebook groups, with the goal of finding more distribution partners,” says tefanko.

“In November 2021, we observed the distribution of malicious wallets using two legitimate Chinese websites. In addition to these distribution vectors, we discovered dozens of other fake wallet websites specifically targeting mobile users. A potential victim may be prompted to download a Trojan Wallet app for the Android or iOS platform.”

The malicious app behaves differently depending on the operating system. On Android, it seems to be targeting new cryptocurrency users who do not yet have a legitimate wallet application installed on their device. On iOS, the victim may have both versions installed, the legitimate one from the App Store and the malicious one from the website.

On iOS, these malicious apps are not available on the App Store; They must be downloaded and installed using configuration profiles, which add an arbitrary, trusted code-signing certificate. On Google Play, based on ESET’s request as a Google App Defense Alliance partner, in January 2022, Google removed 13 malicious applications found on the official store.

The source code of this threat has been leaked and shared on some Chinese websites, which may attract various threat actors and spread it further.

The price of bitcoin has almost halved from its all-time high almost four months ago. It could be time for cryptocurrency investors to panic and withdraw their funds, or it could be time for newbies to jump at the opportunity and buy cryptocurrencies at lower prices.

“If you belong to one of these groups, you should choose carefully which mobile app you should use to manage your funds,” tefanko says.

Source



Related News

Stranger Things: The Duffer brothers would have some ideas for a spin-off

Ahead of Stranger Things season 4, the Duffer brothers reveal they have a super secret idea for a spin-off. This was leaked in an email interview with

WhatsApp: so you can open the Meta application by shaking your Android mobile

It is likely that WhatsApp be one of the platforms that users use every day of the year, since the aforementioned messaging application allows you to

Fortnite Pro’s Racist Video of Gun Arsenal Condemned Online

An esports supporter has been lashed out after a video surfaced online in which a man, allegedly fortnite Champion Series Grand Final Contender Sin, Shows

What does sideloading mean, and how do you sideload apps?

Sideloading is a term you see from time to time talking about Android applications, and it is easy to explain. This means installing the application without

Resident Evil 3 Remake next-gen: upcoming update?

Over the course of this week, a Twitter user said they had a chance to to update his version of Resident Evil 3 Remake next-gen from the digital store of Sony

Freud’s Bones – Review, a journey beyond the psyche

Those who like to explore the world of titles independentand more particularly those our ownthey will certainly not hear in Freud's Bones a new name: This is