Malicious apps are being used to steal crypto from iOS and Android users


The antivirus maker and internet security firm ESET has uncovered a sophisticated malicious cryptocurrency scheme that has been targeting mobile users on Android and iOS since May of last year.
The scheme itself is believed to be the work of one criminal group and it uses malicious apps distributed through fake websites in order to steal Bitcoin and other cryptocurrencies from unsuspecting users. These malicious apps mimic popular cryptocurrency wallets including Metamask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken and OneKey.
Those behind the scheme use ads placed on legitimate websites with misleading articles to promote the fake websites that distribute these copycat wallet apps. However, the cybercriminals have also recruited intermediaries through groups on Telegram and Facebook. While the main goal of the scheme is to steal users’ funds, ESET Research has mainly observed Chinese users being targeted but with cryptocurrencies becoming more popular, the firm’s security researchers expect the techniques used in it to spread to other markets.
The ESET researcher who discovered the scheme, Lukáš Štefanko provided further insight on how it works in a press release, saying:
“These malicious apps also represent another threat to victims, as some of them send secret victim seed phrases to the attackers’ server using an unsecured HTTP connection. This means that victims’ funds could be stolen not only by the operator of this scheme, but also by a different attacker eavesdropping on the same network. We also discovered 13 malicious apps impersonating the Jaxx Liberty wallet. These apps were available on the Google Play store.”
An elaborate scheme
Beginning in May of last year, ESET’s security researchers discovered dozens of trojanized cryptocurrency wallet apps.
What sets this scheme apart from other crypto scams though is the fact that the author of the malware carried out in-depth analysis of legitimate crypto apps in order to insert their own malicious code in places where it would be hard to detect. At the same time, they also ensured that the fake apps they created had the same functionality as the originals.
ESET found dozens of groups promoting malicious copies of cryptocurrency wallets on Telegram since May of 2021. Beginning in October of last year, these same Telegram groups were shared and promoted in at least 56 Facebook groups to look for even more distribution partners. Then in November, ESET spotted these fake cryptocurrency wallet apps being distributed on two legitimate Chinese websites.
These malicious apps also behave differently on Android and iOS. On Android they target new cryptocurrency users that don’t already have a wallet app installed on their devices while on iOS, the victims can have both a legitimate and a malicious wallet app installed.
As the source code of this scheme has been leaked and shared on several Chinese websites, it could attract other cybercriminals to spread it even further. For this reason, users interested in buying, selling and storing cryptocurrencies should only download crypto wallet apps from either the Apple App Store or the Google Play Store.
Audio player loading… The antivirus maker and internet security firm ESET has uncovered a sophisticated malicious cryptocurrency scheme that has been targeting mobile users on Android and iOS since May of last year. The scheme itself is believed to be the work of one criminal group and it uses malicious…
Recent Posts
- DJI’s drone-in-a-box can now launch from moving vehicles
- We might have our first look at the Samsung Galaxy Z Flip 7, but I can’t tell the difference from the Z Flip 6
- AMD’s Radeon 9070 and 9070 XT are gunning for NVIDIA’s mid-range throne
- The Rings of Power season 3 adds Stranger Things’ Jamie Campbell Bower and Heartstopper’s Eddie Marsan to its cast, and I think they’re perfect for two specific roles
- The iPhone 16e doesn’t have MagSafe, but apparently Apple thinks you didn’t want it anyway
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010