Chinese hackers use fake Skype app to target crypto users in new phishing scam

0

[ad_1]

A new phishing scam has emerged in China that uses a fake Skype video app to target crypto users.

According to a report by crypto security analytics firm SlowMist, the Chinese hackers behind the phishing scam used China’s ban on international applications as the basis of their fraud, with many mainland users often searching for these banned applications via third-party platforms.

Social media applications such as Telegram, WhatsApp and Skype are some of the most common applications searched for by mainland users, so scammers often use this vulnerability to target them with fake, cloned applications containing malware developed to attack crypto wallets.

Baidu search results for Skype. Source: Baidu

In its analysis, the SlowMist team found that the recently created fake Skype application displayed version 8.87.0.403, while the latest official version of Skype is 8.107.0.215. The team also discovered that the phishing back-end domain “bn-download3.com” impersonated the Binance exchange on Nov. 23, 2022, later changing to mimic a Skype back-end domain on May 23, 2023. The fake Skype app was first reported by a user who lost “a significant amount of money” to the same scam.

The fake app’s signature revealed that it had been tampered with to insert malware. After decompiling the app, the security team discovered a modified commonly used Android network framework, “okhttp3,” to target crypto users. The default okhttp3 framework handles Android traffic requests, but the modified okhttp3 obtains images from various directories on the phone and monitors for any new images in real time.

The malicious okhttp3 requests users to give access to internal files and images, and as most social media applications ask for these permissions anyway, they often don’t suspect any wrongdoing. Thus, the fake Skype immediately begins uploading images, device information, user ID, phone number and other information to the back end.

Once the fake app has access, it continuously looks for images and messages with Tron (TRX) and Ether (ETH)-like address format strings. If such addresses are detected, they are automatically replaced with malicious addresses pre-set by the phishing gang.

Fake Skype app back end. Source: Slowmist

During SlowMist testing, it was found that the wallet address replacement had stopped, with the phishing interface’s back end shut down and no longer returning malicious addresses.

Related: 5 sneaky tricks crypto phishing scammers used last year

The team also discovered that a Tron chain address (TJhqKzGQ3LzT9ih53JoyAvMnnH5EThWLQB) had received approximately 192,856 Tether (USDT) by Nov. 8, with a total of 110 transactions made to the address. At the same time, another ETH chain address (0xF90acFBe580F58f912F557B444bA1bf77053fc03) received approximately 7,800 USDT in 10 transactions.

The SlowMist team flagged and blacklisted all wallet addresses linked to the scam.

Magazine: Thailand’s $1B crypto sacrifice, Mt. Gox final deadline, Tencent NFT app nixed

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 86,876.28
ethereum
Ethereum (ETH) $ 2,903.68
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.17
bnb
BNB (BNB) $ 855.61
solana
Wrapped SOL (SOL) $ 136.92
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.275251
staked-ether
Lido Staked Ether (STETH) $ 2,906.49
dogecoin
Dogecoin (DOGE) $ 0.149612
cardano
Cardano (ADA) $ 0.414672
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.01
whitebit
WhiteBIT Coin (WBT) $ 57.32
wrapped-steth
Wrapped stETH (WSTETH) $ 3,550.00
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,765.25
bitcoin-cash
Bitcoin Cash (BCH) $ 532.18
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,152.62
usds
USDS (USDS) $ 0.999510
hyperliquid
Hyperliquid (HYPE) $ 33.68
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998865
chainlink
Chainlink (LINK) $ 12.82
leo-token
LEO Token (LEO) $ 9.66
zcash
Zcash (ZEC) $ 495.12
stellar
Stellar (XLM) $ 0.249609
weth
WETH (WETH) $ 2,913.56
wrapped-eeth
Wrapped eETH (WEETH) $ 3,147.34
monero
Monero (XMR) $ 400.68
ethena-usde
Ethena USDe (USDE) $ 0.999051
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,079.33
litecoin
Litecoin (LTC) $ 84.07
hedera-hashgraph
Hedera (HBAR) $ 0.142599
avalanche-2
Avalanche (AVAX) $ 13.99
sui
Sui (SUI) $ 1.50
shiba-inu
Shiba Inu (SHIB) $ 0.000008
dai
Dai (DAI) $ 0.999453
world-liberty-financial
World Liberty Financial (WLFI) $ 0.159999
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
crypto-com-chain
Cronos (CRO) $ 0.108989
usdt0
USDT0 (USDT0) $ 1.00
susds
sUSDS (SUSDS) $ 1.08
the-open-network
Toncoin (TON) $ 1.56
uniswap
Uniswap (UNI) $ 6.09
paypal-usd
PayPal USD (PYUSD) $ 0.999740
polkadot
Polkadot (DOT) $ 2.26
mantle
Mantle (MNT) $ 1.00
canton-network
Canton (CC) $ 0.088941
memecore
MemeCore (M) $ 1.80
bittensor
Bittensor (TAO) $ 309.70
usd1-wlfi
USD1 (USD1) $ 0.999090
aave
Aave (AAVE) $ 176.43
Shares