13 apps removed after researchers uncover Trojan crypto wallet scheme

13 apps removed after researchers uncover Trojan crypto wallet scheme

Research by cyber security firm ESET has uncovered a “sophisticated scheme” that disseminates Trojan apps disguised as popular cryptocurrency wallets.

The malicious scheme targets mobile devices using Android or Apple (iOS) operating systems which become compromised if the user downloads a fake app.

Our top trading bots

According to ESET's research, these malicious apps are distributed through bogus websites, and imitate legitimate crypto wallets, including MetaMask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey.

The firm also discovered 13 malicious apps impersonating the Jaxx Liberty wallet, available on the Google Play Store. Google has since removed the offending apps, which were installed more than 1,100 times, but there are still many more lurking out there on other websites and social media platforms.

The threat actors disseminated their wares through social media groups on Facebook and Telegram, intending to steal crypto assets from their victims. ESET claims to have uncovered “dozens of trojanized cryptocurrency wallet apps,” going back to May 2021. It also stated that the scheme, which it believes is the work of one group, was primarily targeting Chinese users via Chinese websites.

Lukáš Štefanko, the researcher who unraveled the scheme, said that there were other threat vectors, such as sending seed phrases to the attacker’s server using unsecured connections, adding:

“This means that victims' funds could be stolen not only by the operator of this scheme but also by a different attacker eavesdropping on the same network.”

The fake wallet apps behave slightly differently depending on where they are installed. On Android, it targets a new cryptocurrency that the user may not have previously traded, prompting the user to install the appropriate wallet. While on iOS the apps need to be downloaded using arbitrary trusted code-signing certificates circumnavigating Apple’s App Store. This means that the user can have two wallets installed simultaneously, the genuine one and the Trojan, but poses less of a threat since most users rely on App Store verification for their apps.

Related: Hodlers beware! New malware targets MetaMask and 40 other crypto wallets

ESET advises cryptocurrency investors and traders to only install wallets from trusted sources that are linked to the official website of the exchange or company.

In February, Google Cloud unveiled the Virtual Machine Threat Detection (VMTD) system, which scans for and detects “cryptojacking” malware designed to hijack resources to mine digital assets.

According to a January Chainalysis report, cryptojacking accounted for 73% of the total value received by malware-related wallets and addresses between 2017 and 2021.

Keep reading upon Cointelegraph
Dogecoin signals bottoming out as DOGE rebounds 30% in two weeks — What's next?
A brutal correction witnessed in the Dogecoin (DOGE) market between May 2021 and February 2022, which saw the price dropping by almost 85%, appears to have...
EU Commission to remove Russian banks from SWIFT cross-border network
The European Commission announced to remove a number of Russian banks from the Society for Worldwide Interbank Financial Telecommunication (SWIFT) messaging...
U.S. Congressman calls for ‘Broad, bipartisan consensus’ on important issues of digital asset policy
In a letter to the leadership of the United States House Financial Services Committee, ranking member Patrick McHenry took a jab at “inconsistent treatment...
Bitcoin miner Rhodium set for IPO, valued at $1.7 billion
The first initial public offering (IPO) for the crypto industry in 2022 comes from a Texas-based Bitcoin (BTC) mining company, Rhodium Enterprises.In an...
El Salvador buys 21 Bitcoin to celebrate Dec. 21, 2021
The government of El Salvador continues celebrating significant days by buying more Bitcoin (BTC), with President Nayib Bukele announcing a new purchase...
Tiger Global backs $24M funding round for blockchain security firm CertiK
Blockchain security firm CertiK has concluded a $24 million funding round as part of its ongoing efforts to expand its product and security offerings for...
Upgrades, ESG, DeFi usage to help ether outpace bitcoin: Pantera Capital
By Lisa Pauline Mattackal(Reuters) - The Ethereum platform's potential applications, lower environmental impact and technical upgrades are likely to help...
This classic trading pattern signaled that Bitcoin price had hit a top
Traders tend to focus too much on timing the right entry to a trade, but very few focus on developing a strategy for exiting positions. If one sells too...
Spartan Protocol exploit results in loss of $30M
Spartan Protocol, a liquidity platform for synthetic assets on the Binance Smart Chain, was drained of $30 million in a coordinated attack on its liquidity...
Goldman Sachs CEO believes Bitcoin regulations are set for a 'big evolution'
David Solomon, CEO of Goldman Sachs has forecast a “big evolution” in how the U.S. government regulates Bitcoin and other cryptocurrencies, in relation...
Litecoin Climbs 10% In Bullish Trade
Investing.com - Litecoin was trading at $222.857 by 18:04 (22:04 GMT) on the Investing.com Index on Monday, up 10.21% on the day. It was the largest one-day...
A year into the pandemic: How Argentina's economy struggled while its crypto ecosystem flourished
The year 2020 will go down in history as the beginning of the COVID-19 pandemic and the way it affected the Argentine economy. But it is also true that...
Jack Ma and Steve Wozniak Have Different Views On BTC But Agree on Blockchain
Lots of the financial world’s guru claim that the price of bitcoin is highly dependent on what people think it is worth. And, as it is known, people’s...
Ripple’s Price Soared & Dropped Amid Coinbase-Related Rumors
On Monday, March 5, the third most popular, according to Coinmarketcap.com, crypto-coin Ripple experienced both a leap and a drop as rumors concerning...
The Board Of Directors And The President Of Tezos Foundation Changed
Two members of the board of the Tezos Foundation, including its president, Johann Gevers, voluntarily resigned.They will be replaced by a member of the...