Malicious cryptocurrency scheme targets Android and iOS users



Researchers have discovered a sophisticated malicious cryptocurrency scheme that targets mobile devices running Android or iOS.

Malicious apps are distributed through fake websites and imitate legitimate wallet services such as MetaMask, Coinbase, Trust Wallet, TokenPocket, BitPay, ImToken and OneKey. Fake websites are promoted with advertisements on legitimate sites by using deceptive articles.

Researchers say threatening actors are also recruiting middlemen through Telegram and Facebook groups to help distribute the malicious scheme. ESET Research says that the primary target of malicious apps is to steal users’ funds and recently, the scheme has largely targeted Chinese users. As cryptocurrencies gain popularity, ESET expects the technology to spread to other markets.

“Starting in May 2021, our research uncovered dozens of Trojanized cryptocurrency wallet apps,” says ESET researcher Lukas Otefanko.



“It is a sophisticated attack vector because the author of the malware has done a thorough analysis of the legitimate applications abused in this scheme, allowing their malicious code to be inserted in places where it would be difficult to detect, as well as to ensure Do that as such have been crafted. The apps had the same functionality as the original. At this point, ESET Research believes this is likely the work of a criminal group.”

He says malicious apps also represent another threat, as some of them send secret prey seed phrases to attackers’ servers using unsecured HTTP connections. This means that the victim’s funds can be stolen both by the operator of the scheme and by a different attacker on the same network.

“We also discovered 13 malicious apps impersonating the Jaxx Liberty Wallet. These apps were available on the Google Play Store,” tefanko says.

On Telegram, a free and popular multi-platform messaging app with advanced privacy and encryption features, ESET found dozens of groups promoting malicious copies of a cryptocurrency mobile wallet. The research company assumes that these groups were created by the threat actor behind the plan in search of further distribution partners. ESET says this activity has continued through May 2021.

“As of October 2021, we found that these Telegram groups were shared and promoted in at least 56 Facebook groups, with the goal of finding more distribution partners,” says tefanko.

“In November 2021, we observed the distribution of malicious wallets using two legitimate Chinese websites. In addition to these distribution vectors, we discovered dozens of other fake wallet websites specifically targeting mobile users. A potential victim may be prompted to download a Trojan Wallet app for the Android or iOS platform.”

The malicious app behaves differently depending on the operating system. On Android, it seems to be targeting new cryptocurrency users who do not yet have a legitimate wallet application installed on their device. On iOS, the victim may have both versions installed, the legitimate one from the App Store and the malicious one from the website.

On iOS, these malicious apps are not available on the App Store; They must be downloaded and installed using configuration profiles, which add an arbitrary, trusted code-signing certificate. On Google Play, based on ESET’s request as a Google App Defense Alliance partner, in January 2022, Google removed 13 malicious applications found on the official store.

The source code of this threat has been leaked and shared on some Chinese websites, which may attract various threat actors and spread it further.

The price of bitcoin has almost halved from its all-time high almost four months ago. It could be time for cryptocurrency investors to panic and withdraw their funds, or it could be time for newbies to jump at the opportunity and buy cryptocurrencies at lower prices.

“If you belong to one of these groups, you should choose carefully which mobile app you should use to manage your funds,” tefanko says.

Source



Related News

Corsair Launches 8TB Capacity MP600 Pro XT SSD

Corsair has quietly added another 8TB capacity model to its premium MP600 Pro XT PCIe 4.0 drive family. The new drives offer enormous capacity when it comes

How to change the function of the Android home button

Those who have a cell phone with an operating system Android they know that the home button is a great ally when they want to go directly to the main screen

Adrod 13 Installer – Does this Android 13 installer really destroy your phone?

With the arrival of Android 13 it would not be a surprise that also some come to light scams inspired by this new version of the operating system.

Draft bill lets non-banks issue stablecoins, bans algorithmic coins for two years

WASHINGTON — A nearly finalized law between Democrats and Republicans on the House Financial Services Committee would authorize the Federal Reserve to license

Windows 11 blocks undervolting and overvolting on MSI cards

According to what is reported by the users of the MSI_Gaming subreddit, it seems that Microsoft has recently released a new update of Windows 11 that blocks

‘Adroid 13’ for TikTok meme pretends to brick phone: Please don’t install apk at random

Android 13 is the latest version of the world's most popular smartphone operating system, and as is the case with most new software versions, there are always