💎 Fed’s first rate cut since 2020 set to trigger market. Find undervalued gems with Fair ValueSee Undervalued Stocks

Phishing Attacks Steal Crypto Funds Through Fake Skype App Download

Published 13/11/2023, 20:33
© Reuters.  Phishing Attacks Steal Crypto Funds Through Fake Skype App Download
USDT/USD
-

Benzinga - Blockchain security firm SlowMist announced a new phishing attack involving a fake Skype app that stole crypto funds from an unsuspecting victim.

Industry titans BlackRock, DTCC, OCC, State Street, Société Générale, Hedera, Citi, BMO, Northern Trust, Citibank, Amazon, S&P Global, Google, Invesco, and Moody’s will join Benzinga on Nov. 13 for Fintech Deal Day and Nov. 14 for Future of Digital Assets. Secure a spot here to join them.

What Happened: Phishing attacks using fake apps happen frequently, especially in regions where the download of apps is restricted in Google Play and instead encourages online downloads making the users' data vulnerable.

SlowMist received the information directly from the victim who said the phishing incident happened after he downloaded what he assumed to be a Skype app.

The report used MistTrack for analysis and found the TRON chain address (TJhqKzGQ3LzT9ih53JoyAvMnnH5EThWLQB) received around 192,856 USDT with 110 deposit transactions. The address has still a balance remaining with a most recent transaction on Nov. 8, 2023.

Also, an Ethereum chain address (0xF90acFBe580F58f912F557B444bA1bf77053fc03) received around 7,800 USDT in 10 deposit transactions. The majority of the funds were transferred out through BitKeep’s Swap service.

Read More: Bitcoin, Ethereum Exchange Bitfinex Users Targeted In 'Minor' Phishing Attack After Support Agent's Account Breached

The report added that there are certain regions in China more prone to such attacks, which is caused by the inaccessibility of Google Play in China, making users search and download apps directly from the internet.

The apps available online are not limited to wallets and exchanges; social media applications such as Telegram, WhatsApp and Skype are also targeted.

How Did It Happen: After SlowMist’s investigation, it was revealed the app's certificate effective date was newly created in September and signature information indicated a Chinese origin. After a Baidu search, the fake app’s multiple sources were found to be in line with the one provided by the victim.

The report added, “Since social apps need to transfer files and make calls, users generally do not suspect these activities. After obtaining user permissions, the fake Skype immediately begins uploading images, device information, user ID, phone number, and other information to the backend.”

This phishing domain is connected to the app that initially replicated the crypto exchange Binance in November 2022 before switching to mimic Skype's backend in May 2023.

The SlowMist report added, “Further analysis revealed that ‘bn-download[number]’ is a series of fake domains used by this phishing gang specifically for Binance phishing, indicating that this gang is a repeat offender targeting Web3 specifically.”

Also Read: This Company Is Using AI To Establish Trust In A Digitally Connected World

This news comes on the heels of Benzinga’s Future Of Digital Assets Event in New York scheduled on Nov. 14. Attend and learn more about phishing attacks and how important a secure and transparent network is. The gathering is seen as pivotal for the digital assets community. The event will spotlight the latest trends, innovations, and challenges in the digital asset realm.

Photo: Shutterstock

© 2023 Benzinga.com. Benzinga does not provide investment advice. All rights reserved.

Read the original article on Benzinga

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.