Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Sophisticated Scam App on Google Play Tricks Over 150 Users, Stealing $70K in Crypto

Sophisticated Scam App on Google Play Tricks Over 150 Users, Stealing $70K in Crypto

EthnewsEthnews2024/10/01 11:31
By:By SyofriEdited by AnnJoy Makena
  • A fraudulent app called “Mestox Calculator” impersonated WalletConnect on Google Play, deceiving users and stealing over $70,000 from about 150 victims.
  • Using tactics like disguising as a calculator and posting fake reviews, the app avoided detection and manipulated user trust for five months.

In a concerning revelation, the crypto community was alerted to a significant security breach involving a fake application on Google Play that masqueraded as WalletConnect, a popular open-source protocol. This malicious app duped more than 150 individuals into losing collectively over $70,000 worth of cryptocurrency . The deception was uncovered by cybersecurity experts at Check Point Research (CPR), who reported that the app was downloaded over 10,000 times before its eventual removal from the platform.

Unveiling the Scam: Mestox Calculator’s Hidden Agenda

The journey of the fake app began on March 21, 2024, when it first appeared on Google Play as “Mestox Calculator.” Over time, it underwent several transformations, with its final guise being a deceptive version of a WalletConnect application. Despite these changes, the app cleverly retained its original URL, which misleadingly pointed to a benign-looking calculator website. This strategic choice allowed the app to bypass Google’s stringent review processes, which would typically vet new applications for security threats.

CPR’s investigation highlighted that the scammers utilized advanced social engineering techniques to build credibility. The app featured fake reviews and professional-looking branding, enhancing its visibility and perceived legitimacy in search results. This manipulation led users to believe they were downloading a genuine crypto tool, further facilitated by the app’s name exploiting the trust associated with the WalletConnect brand.

The Mechanics of Fraud

Upon installation, the app prompted users to connect their crypto wallets and grant various permissions, which seemed routine for crypto-related applications. However, this was a ruse to initiate sophisticated draining techniques that triggered unauthorized transactions. The victims, unaware of the app’s true nature, unwittingly approved these transactions, allowing the fraudsters to directly transfer funds out of their wallets.

Interestingly, the app targeted users based on their IP address and device type. Those who met the criteria were redirected to a backend that harbored the malicious MS Drainer software, which facilitated the fraudulent transactions.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!