13 apps removed after researchers uncover Trojan crypto wallet scheme

13 apps removed after researchers uncover Trojan crypto wallet scheme

Research by cyber security firm ESET has uncovered a “sophisticated scheme” that disseminates Trojan apps disguised as popular cryptocurrency wallets.

The malicious scheme targets mobile devices using Android or Apple (iOS) operating systems which become compromised if the user downloads a fake app.

Our top trading bots

According to ESET's research, these malicious apps are distributed through bogus websites, and imitate legitimate crypto wallets, including MetaMask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey.

The firm also discovered 13 malicious apps impersonating the Jaxx Liberty wallet, available on the Google Play Store. Google has since removed the offending apps, which were installed more than 1,100 times, but there are still many more lurking out there on other websites and social media platforms.

The threat actors disseminated their wares through social media groups on Facebook and Telegram, intending to steal crypto assets from their victims. ESET claims to have uncovered “dozens of trojanized cryptocurrency wallet apps,” going back to May 2021. It also stated that the scheme, which it believes is the work of one group, was primarily targeting Chinese users via Chinese websites.

Lukáš Štefanko, the researcher who unraveled the scheme, said that there were other threat vectors, such as sending seed phrases to the attacker’s server using unsecured connections, adding:

“This means that victims' funds could be stolen not only by the operator of this scheme but also by a different attacker eavesdropping on the same network.”

The fake wallet apps behave slightly differently depending on where they are installed. On Android, it targets a new cryptocurrency that the user may not have previously traded, prompting the user to install the appropriate wallet. While on iOS the apps need to be downloaded using arbitrary trusted code-signing certificates circumnavigating Apple’s App Store. This means that the user can have two wallets installed simultaneously, the genuine one and the Trojan, but poses less of a threat since most users rely on App Store verification for their apps.

Related: Hodlers beware! New malware targets MetaMask and 40 other crypto wallets

ESET advises cryptocurrency investors and traders to only install wallets from trusted sources that are linked to the official website of the exchange or company.

In February, Google Cloud unveiled the Virtual Machine Threat Detection (VMTD) system, which scans for and detects “cryptojacking” malware designed to hijack resources to mine digital assets.

According to a January Chainalysis report, cryptojacking accounted for 73% of the total value received by malware-related wallets and addresses between 2017 and 2021.

Keep reading upon Cointelegraph
South Korean crypto market grows to $45.9B in 2021 despite strict regulations
South Korea’s crypto market grew to 55 trillion won ($45.9 billion) by the end of 2021, as per a new study from the country’s chief financial regulator,...
Blockchain is just a database without crypto, legal expert says
Blockchain can’t be separated from crypto in a progressive manner because extracting blockchain from crypto diminishes the former to a glorified database,...
Here’s why Bitcoin traders expect choppy markets for the remainder of 2021
Inflation concerns and a general sense of trepidation about the future of the global economy continue to put a damper on Bitcoin and altcoin prices and...
Miami will hand out free Bitcoin to residents from profits on city coin
Every Miami resident with a digital wallet will be eligible to receive a Bitcoin dividend according to Mayor Francis Suarez. “We’re going to be the very...
Grayscale adds SOL and UNI to Digital Large Cap Fund portfolio
Grayscale Investments, a New-York based crypto asset manager, now includes Solana’s SOL and Uniswap’s UNI tokens in its Grayscale Digital Large Cap Fund...
Billionaire investor bullish on Bitcoin: ‘Crypto is here to stay’
Orlando Bravo, co-founder and managing partner of private equity firm Thoma Bravo, expressed his unwavering endorsement of the cryptocurrency market in...
Cardano’s Alonzo hard fork was a success but real utility could be a while
Cardano (ADA) reached a major milestone in its roadmap on Sep. 13 as its blockchain launched Plutus-powered smart contracts as a part of the Alonzo hard...
Three reasons why the price of Elrond (EGLD) is hitting new daily highs
Decentralized finance-focused protocols are seeing a sustained upward move, and the momentum appears to be picking up pace now that the NFT sector has cooled...
Bitcoin gears up for $47K assault — Can BTC price overcome make-or-break resistance?
Bitcoin (BTC) looked set to challenge critical $47,000 resistance on Tuesday amid a perfect storm of dwindling supply and “exhausted” bears.BTC/USD 1-hour...
Nifty News: Dolce & Gabbana's historic NFTs, '26 minute' CryptoPunk flip, FTX spammed
Dolce & Gabbana knocking on the Dior of NFTsLuxury Italian fashion house Dolce & Gabbana is entering the NFT sector with a nine-piece collection of tokenized...
Cointelegraph Consulting: Going down the Metaverse
As nonfungible token sales appear reanimated after a nearly two-month dry spell from their apex in May, a particular NFT application is gaining popularity...
Cardano Climbs 13% In Bullish Trade
Investing.com - Cardano was trading at $2.375325 by 18:28 (22:28 GMT) on the Investing.com Index on Thursday, up 13.26% on the day. It was the largest one-day...
Over 3,000 ATMs in Beijing can now convert digital yuan into cash
China continues apace with the adoption of its central bank digital currency (CBDC) as major banks launch a significant batch of digital yuan-powered ATMs.The...
Travala launches decentralized home-sharing service — will it be the next Airbnb?
Pro-crypto travel booking agency Travala.com is releasing a decentralized property rental service.In a Wednesday announcement, Travala said it had partnered...
Qtum price rallies 160% as the project's focus on DeFi pays off
After rallying 1.510% in 2021, QTUM price hit a $35.70 all-time high on May 7. This relatively obscure altcoin launched in September 2017 is a fork of the...