Hackers are using Web3 backdoor wallets to steal seed phrases from iOS/Android users



A Chinese-speaking, technically proficient threat actor distributes backdoor applications to extort cash from victims in a newly discovered large-scale operation.

Trusted security researchers have shared details of a large-scale operation launched by a technologically advanced, sophisticated threat actor. The actor distributes backdoor applications through fake versions of authentic cryptocurrency wallet websites to withdraw funds. The activity cluster, dubbed SeaFlower, is reportedly targeting iOS and Android users.

The Confident researchers noted that Trojanized cryptocurrency apps are very similar to their real versions. However, they contain a backdoor that can steal a user’s security step, allowing attackers to access their digital assets.

attack method

The SeaFlower operation leverages website cloning, SEO poisoning, and black SEO techniques to distribute Trojanized apps to a wide range of users. Targeted applications include the iOS and Android versions of MetaMask, Coinbase Wallet, ImToken and TokenPocket.

These apps are distributed through Chinese search engines such as Sogou and Baidu. The search terms have been rigged, so when someone searches for Download Metamask iOS, the drive-by download page results appear at the top of the first page.

Unsuspecting users stumble upon suspicious sites, which act as a conduit to entice victims to download Trojanized versions of the Wallet app. These apps have been modified to look similar to the original versions but have additional code to extract the seed phrase and send to remote domains.



Attackers can promote backdoor apps and use malware on social media platforms and forums, but the major distribution channel is search engines.

seaflower purpose

According to a blog post by Taha Karim of Confident, the main objective behind this campaign appears to be to modify the Web3 wallet with backdoor code to take out the seed phrase. SeaFlower operators have also engineered the activity to target iOS users through provisioning profiles to enable apps for sideloading on the device.

For your information, provisioning profiles help to connect tools and developers to an unprivileged development team. In this way, the tools can be used to test app code and add malicious apps to the devices.

Chinese connection

Analysis of source code comments, macOS usernames, and the involvement of Alibaba’s CDN (content delivery network) in backdoor coding ties this campaign with a yet-to-be-revealed Chinese-speaking organization.

The researchers claim they discovered the campaign in March 2022 and refer to SeaFlower as “the most technologically sophisticated threat targeting Web3 users, right after the infamous Lazarus group.”

Why sea flowers?

As to why the Confident researchers dubbed Seaflower Activity, they noted that one of the .dylib files injected into the Trojanized MetaMask app’s Mach-O leaked a macOS username named “zhang heik”. When he Googled the term, several Chinese language references came up, one of which was a character in the Chinese novel “Tibetan Sea Flower”.

security measures

Chinese hackers have always been known to be dangerous and highly sophisticated. It may be because of the unlimited resources supported by the government or they are good at it. Nevertheless, downloading apps and software from third-party markets should be strictly avoided.

Always download mobile apps from official stores: Apple Appstore and Play Store. Never install or accept random provisioning profiles on your iPhone, as you saw in this blog post, they allow the download of unverified software that could potentially steal your crypto.

Taha Karim – Confidant

More Chinese Hackers in the News

  1. Iranian and Chinese state hackers exploiting Log4j vulnerability
  2. Russian-language hacking forums are heating up to Chinese hackers
  3. Chinese APT Group FoundCore RAT . is spying on the vietnam army with
  4. Microsoft disrupts the activities of Chinese hackers by seizing 42 websites
  5. Unofficial micropatch for Follina released as exploit of Chinese hackers 0-day

Source



Related News

Σε τι χρησιμεύει η θύρα USB του ρούτερ; Μάθετε πώς να αξιοποιήσετε στο έπακρο

Σε προηγούμενες περιπτώσεις, είχε ήδη αναφερθεί ποιες είναι οι πιθανές λειτουργίες της θύρας USB της Smart TV σας. Τώρα σας φέρνουμε έναν παρόμοιο οδηγό, αλλά

Έχεις πολλά! (2023) – κριτική ταινίας [Canal+]. Μια τυπική κωμωδία για την πολωνική νοοτροπία

The movie "You're in luck!" tells the story of the Bednarski family, who learn that their deceased grandfather Józef (Mikołaj Grabowski) was buried with a

Η χειρουργική βελόνα ARC χρησιμοποιεί ένα κατευθυνόμενο άκρο για να χτυπήσει το στόχο

Οι χειρουργοί στρέφονται ολοένα και περισσότερο σε λιγότερο επεμβατικές τεχνικές, όπως η χρήση μακριών, λεπτών βελόνων -- αντί για νυστέρι -- για την επίτευξη στόχων εντός του

Το Pikmin 4 ανακοινώθηκε στο Nintendo Direct

Κατά τη διάρκεια του Nintendo Direct είδαμε μια σειρά από πολύ τεράστια τρέιλερ. Ένα από αυτά έδειξε το Pikmin 4, που έρχεται στο Nintendo Switch κατά τη διάρκεια του 2023. Μετά από αυτό

Τα Παιχνίδια Google Play για Windows λαμβάνουν πολλές βελτιώσεις μαζί με την ανοιχτή έκδοση beta

Ξεκινώντας τη χρονιά, τα παιχνίδια Android ήρθαν επίσημα στα Windows 10 και 11 μέσω των Παιχνιδιών Google Play. Ωστόσο, μέχρι τώρα αυτή η νέα δυνατότητα παρέμενε κλειστή