By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign
Tech News

Crypto Scam App Disguised as WalletConnect Steals $70K in Five-Month Campaign

By Viral Trending Content 5 Min Read
Share
SHARE

Sep 28, 2024Ravie LakshmananCryptocurrency / Mobile Security

Crypto Scam App

Cybersecurity researchers have discovered a malicious Android app on the Google Play Store that enabled the threat actors behind it to steal approximately $70,000 in cryptocurrency from victims over a period of nearly five months.

The dodgy app, identified by Check Point, masqueraded as the legitimate WalletConnect open-source protocol to trick unsuspecting users into downloading it.

“Fake reviews and consistent branding helped the app achieve over 10,000 downloads by ranking high in search results,” the cybersecurity company said in an analysis, adding it’s the first time a cryptocurrency drainer has exclusively targeted mobile device users.

Over 150 users are estimated to have fallen victim to the scam, although it’s believed that not all users who downloaded the app were impacted by the cryptocurrency drainer.

Cybersecurity

The campaign involved distributing a deceptive app that went by several names such as “Mestox Calculator,” “WalletConnect – DeFi & NFTs,” and “WalletConnect – Airdrop Wallet” (co.median.android.rxqnqb).

While the app is no longer available for download from the official app marketplace, data from SensorTower shows that it was popular in Nigeria, Portugal, and Ukraine, and linked to a developer named UNS LIS.

The developer has also been associated with another Android app called “Uniswap DeFI” (com.lis.uniswapconverter) that remained active on the Play Store for about a month between May and June 2023. It’s currently not known if the app had any malicious functionality.

Crypto Scam App

However, both apps can be downloaded from third-party app store sources, once again highlighting the risks posed by downloading APK files from other marketplaces.

Once installed, the fake WallConnect app is designed to redirect users to a bogus website based on their IP address and User-Agent string, and if so, redirect them a second time to another site that mimics Web3Inbox.

Users who don’t meet the required criteria, including those who visit the URL from a desktop web browser, are taken to a legitimate website to evade detection, effectively allowing the threat actors to bypass the app review process in the Play Store.

Besides taking steps to prevent analysis and debugging, the core component of the malware is a cryptocurrency drainer known as MS Drainer, which prompts users to connect their wallet and sign several transactions to verify their wallet.

Crypto Scam App

The information entered by the victim in each step is transmitted to a command-and-control server (cakeserver[.]online) that, in turn, sends back a response containing instructions to trigger malicious transactions on the device and transfer the funds to a wallet address belonging to the attackers.

“Similar to the theft of native cryptocurrency, the malicious app first tricks the user into signing a transaction in their wallet,” Check Point researchers said.

“Through this transaction, the victim grants permission for the attacker’s address 0xf721d710e7C27323CC0AeE847bA01147b0fb8dBF (the ‘Address’ field in the configuration) to transfer the maximum amount of the specified asset (if allowed by its smart contract).”

In the next step, the tokens from the victim’s wallet are transferred to a different wallet (0xfac247a19Cc49dbA87130336d3fd8dc8b6b944e1) controlled by the attackers.

Cybersecurity

This also means that if the victim does not revoke the permission to withdraw tokens from their wallet, the attackers can keep withdrawing the digital assets as soon as they appear without requiring any further action.

Check Point said it also identified another malicious app exhibiting similar features “Walletconnect | Web3Inbox” (co.median.android.kaebpq) that was previously available on Google Play Store in February 2024. It attracted more than 5,000 downloads.

“This incident highlights the growing sophistication of cybercriminal tactics, particularly in the realm of decentralized finance, where users often rely on third-party tools and protocols to manage their digital assets,” the company noted.

“The malicious app did not rely on traditional attack vectors like permissions or keylogging. Instead, it used smart contracts and deep links to silently drain assets once users were tricked into using the app.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Up to 40% off in UGREEN’s Black Friday and Cyber Monday Big Sale

ServiceNow + Microsoft announce new agentic capabilities at Ignite

Gemini Coder 2 Build Mode : Free AI Coding Tool You Need to Try

Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices

Netherlands suspends Nexperia takeover after dialogue with China

TAGGED: Android, App Security, cryptocurrency, Cyber Security, Cybersecurity, DeFi, Google Play Store, Internet, Malware, mobile security
Share This Article
Facebook Twitter Copy Link
Previous Article Crypto Fear & Greed Index jumps back into greed territory
Next Article Kumar Arch Tech files draft papers to raise Rs 740 crore via IPO
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Up to 40% off in UGREEN’s Black Friday and Cyber Monday Big Sale
Tech News
Rangers now in talks to sign "fantastic" January target who Danny Rohl loves
Sports
Nvidia shares rise after quarterly earnings, calming bubble anxiety
Business
Ammunition and explosives but unclear numbers: What we know about Italian military aid to Ukraine
World News
Meet the Ballpark real estate broker taking on CoStar and LoopNet
Business
‘As if they own the sea’: Bali moves to stop resorts from blocking public beaches
Travel
ROG Xbox Ally and Ally X Get More Power and Performance Management Options in New Update
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Up to 40% off in UGREEN’s Black Friday and Cyber Monday Big Sale

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Up to 40% off in UGREEN’s Black Friday and Cyber Monday Big Sale
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?