Značka: mobile

13 apps removed after researchers uncover Trojan crypto wallet scheme

Research by cyber security firm ESET has uncovered a “sophisticated scheme” that disseminates Trojan apps disguised as popular cryptocurrency wallets.The malicious scheme targets mobile devices using Android or Apple (iOS) operating systems which become compromised if the user downloads a fake app.According to ESET’s research, these malicious apps are distributed through bogus websites, and imitate legitimate crypto wallets, including MetaMask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey.The firm also discovered 13 malicious apps impersonating the Jaxx Liberty wallet, available on the Google Play Store. Google has since removed the offending apps, which were installed more than 1,100 times, but there are still many more lurking out there on other websites and social media platforms.The threat actors disseminated their wares through social media groups on Facebook and Telegram, intending to steal crypto assets from their victims. ESET claims to have uncovered “dozens of trojanized cryptocurrency wallet apps,” going back to May 2021. It also stated that the scheme, which it believes is the work of one group, was primarily targeting Chinese users via Chinese websites.Lukáš Štefanko, the researcher who unraveled the scheme, said that there were other threat vectors, such as sending seed phrases to the attacker’s server using unsecured connections, adding:“This means that victims’ funds could be stolen not only by the operator of this scheme but also by a different attacker eavesdropping on the same network.”The fake wallet apps behave slightly differently depending on where they are installed. On Android, it targets a new cryptocurrency that the user may not have previously traded, prompting the user to install the appropriate wallet. While on iOS the apps need to be downloaded using arbitrary trusted code-signing certificates circumnavigating Apple’s App Store. This means that the user can have two wallets installed simultaneously, the genuine one and the Trojan, but poses less of a threat since most users rely on App Store verification for their apps. Related: Hodlers beware! New malware targets MetaMask and 40 other crypto walletsESET advises cryptocurrency investors and traders to only install wallets from trusted sources that are linked to the official website of the exchange or company.In February, Google Cloud unveiled the Virtual Machine Threat Detection (VMTD) system, which scans for and detects “cryptojacking” malware designed to hijack resources to mine digital assets.According to a January Chainalysis report, cryptojacking accounted for 73% of the total value received by malware-related wallets and addresses between 2017 and 2021.

Čítaj viac

CBDC wallet tops mobile app store charts in China

The official digital yuan wallet app that was released as a pilot version to be used in select cities has still managed to top app store charts in its first week.Developed by the Digital Currency Research Institute of the People’s Bank of China (PBoC), the app became available for download on Chinese Android and Apple app stores last Tuesday.The app is still in an experimental phase and is only accessible to select individuals through authorized e-CNY service providers. While anyone in China could download the app, its usage is limited to select cities. Despite these limitations, the South China Morning Post reported that e-CNY managed to become the most downloaded app on Apple’s App Store one day after its launch, surpassing Tencent’s super app WeChat. It was dethroned by video-sharing app Kuaishou on Saturday.The app enjoyed similar success in Xiaomi’s mobile app store, a popular platform for Chinese Android users. It topped the list within a day before falling to the second spot on Monday according to market researcher Qimai. The app ranked 43rd on Huawei’s mobile store on Monday, jumping 10 spots in a day.Related: China wants US senators to ‘stop making trouble’ out of digital yuanAfter years of development, China started digital yuan pilots in April 2020 and since has become a pioneer in central bank digital currency (CBDC) development, to the point where the country plans to enable CBDC payments at the 2022 Winter Olympic Games in Beijing, scheduled for next month. The digital yuan even became a topic of debate for several United States senators, who have signed a letter urging Olympic officials to forbid American athletes from using the digital yuan during the event.

Čítaj viac
Načítava

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy