Telegram (AI) YouTube Facebook X
Ру
Chinese hackers create a fake Skype app to steal cryptocurrencies

Chinese hackers create a fake Skype app to steal cryptocurrencies

SlowMist researchers uncovered a counterfeit Skype app used by Chinese hackers to steal hundreds of thousands of dollars across various cryptocurrencies.

The phishing operators exploit the country’s ban on international messaging apps, forcing users to download them from unofficial sources.

3ff8fba4-ea9f-4a3e-b048-b2b2734e274a
Data: Baidu.

According to SlowMist, the malicious Skype carried version number 8.87.0.403, while the latest version of the real app is 8.107.0.215. From November 2022 to May 2023, the phishing internal domain bn-download3.com used by the hackers posed as the Binance exchange.

Researchers found that the malicious software modified the widely used Android networking library okhttp3 to target cryptocurrency holders.

Using this, the attackers could access internal files and images, as well as device system information. This enabled them to monitor messages containing address-like strings such as TRX and ETH. Later, wallets were swapped for ones owned by the hackers.

During the analysis, SlowMist identified and blacklisted more than 100 malicious addresses related to this scam. In particular, one of the Tron wallets received 110 transactions worth over 192,856 USDT by November 8.

0_QCevom45i38lBJon
Data: SlowMist.

Another ETH address received 7,800 USDT across 10 deposit transactions.

Earlier in January, users became victims of espionage by a trojanized Telegram.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK