Malicious cryptocurrency scheme targets Android and iOS users



Researchers have discovered a sophisticated malicious cryptocurrency scheme that targets mobile devices running Android or iOS.

Malicious apps are distributed through fake websites and imitate legitimate wallet services such as MetaMask, Coinbase, Trust Wallet, TokenPocket, BitPay, ImToken and OneKey. Fake websites are promoted with advertisements on legitimate sites by using deceptive articles.

Researchers say threatening actors are also recruiting middlemen through Telegram and Facebook groups to help distribute the malicious scheme. ESET Research says that the primary target of malicious apps is to steal users’ funds and recently, the scheme has largely targeted Chinese users. As cryptocurrencies gain popularity, ESET expects the technology to spread to other markets.

“Starting in May 2021, our research uncovered dozens of Trojanized cryptocurrency wallet apps,” says ESET researcher Lukas Otefanko.



“It is a sophisticated attack vector because the author of the malware has done a thorough analysis of the legitimate applications abused in this scheme, allowing their malicious code to be inserted in places where it would be difficult to detect, as well as to ensure Do that as such have been crafted. The apps had the same functionality as the original. At this point, ESET Research believes this is likely the work of a criminal group.”

He says malicious apps also represent another threat, as some of them send secret prey seed phrases to attackers’ servers using unsecured HTTP connections. This means that the victim’s funds can be stolen both by the operator of the scheme and by a different attacker on the same network.

“We also discovered 13 malicious apps impersonating the Jaxx Liberty Wallet. These apps were available on the Google Play Store,” tefanko says.

On Telegram, a free and popular multi-platform messaging app with advanced privacy and encryption features, ESET found dozens of groups promoting malicious copies of a cryptocurrency mobile wallet. The research company assumes that these groups were created by the threat actor behind the plan in search of further distribution partners. ESET says this activity has continued through May 2021.

“As of October 2021, we found that these Telegram groups were shared and promoted in at least 56 Facebook groups, with the goal of finding more distribution partners,” says tefanko.

“In November 2021, we observed the distribution of malicious wallets using two legitimate Chinese websites. In addition to these distribution vectors, we discovered dozens of other fake wallet websites specifically targeting mobile users. A potential victim may be prompted to download a Trojan Wallet app for the Android or iOS platform.”

The malicious app behaves differently depending on the operating system. On Android, it seems to be targeting new cryptocurrency users who do not yet have a legitimate wallet application installed on their device. On iOS, the victim may have both versions installed, the legitimate one from the App Store and the malicious one from the website.

On iOS, these malicious apps are not available on the App Store; They must be downloaded and installed using configuration profiles, which add an arbitrary, trusted code-signing certificate. On Google Play, based on ESET’s request as a Google App Defense Alliance partner, in January 2022, Google removed 13 malicious applications found on the official store.

The source code of this threat has been leaked and shared on some Chinese websites, which may attract various threat actors and spread it further.

The price of bitcoin has almost halved from its all-time high almost four months ago. It could be time for cryptocurrency investors to panic and withdraw their funds, or it could be time for newbies to jump at the opportunity and buy cryptocurrencies at lower prices.

“If you belong to one of these groups, you should choose carefully which mobile app you should use to manage your funds,” tefanko says.

Source



Related News

The first MacBook Pro with M2 are already reaching their users

On June 6, Apple announced that some MacBook Pro models would incorporate the new M2 chip, which guarantees that the interior of these computers will be

Why your e-mail is becoming more and more dangerous

No doubt the email It is something we use constantly. We use it to be in contact with other people or with companies, but also to simply be able to register

Google says Apple and Android phones have been hacked by Italian spyware. hacking

Alphabet Inc's Google said in a new report that hacking tools from an Italian company were used to spy on Apple and Android smartphones in Italy and Kazakhstan.

Google says Slice payments app spies photos, audio records and call history

Fintech company Slice, which has introduced itself as an alternative to credit cards, has come under scrutiny after Google alerted users that the app was

This Premium Wear OS 3 Smartwatch Beats the Pixel Watch, But I Won’t Buy It

While I was expecting to see brand new smartwatches running Wear OS 3 in the coming months, I wasn't expecting them as soon as July, and I'm certainly looking