Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

NAACP calls on Memphis officials to halt operations at xAI’s ‘dirty data center’

May 31, 2025

Meta plans to automate many of its product risk assessments

May 31, 2025

Legends Struggles in Box Office Bow, Lilo & Stitch No. 1

May 31, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » Chinese Android Phones Shipped with Fake WhatsApp, Telegram Apps Targeting Crypto Users
Cybersecurity

Chinese Android Phones Shipped with Fake WhatsApp, Telegram Apps Targeting Crypto Users

HarishBy HarishApril 16, 2025No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


Cheap Android smartphones manufactured by Chinese companies have been observed pre-installed with trojanized apps masquerading as WhatsApp and Telegram that contain cryptocurrency clipper functionality as part of a campaign since June 2024.

While using malware-laced apps to steal financial information is not a new phenomenon, the new findings from Russian antivirus vendor Doctor Web point to significant escalation where threat actors are directly targeting the supply chain of various Chinese manufacturers to preload brand new devices with malicious apps.

“Fraudulent applications were detected directly in the software pre-installed on the phone,” the company said. “In this case, the malicious code was added to the WhatsApp messenger.”

Cybersecurity

A majority of the compromised devices are said to be low-end phones that mimic well-known premium models from Samsung and Huawei with names like S23 Ultra, S24 Ultra, Note 13 Pro, and P70 Ultra. At least four of the affected models are manufactured under the SHOWJI brand.

The attackers are said to have used an application to spoof the technical specification displayed on the About Device page, as well as hardware and software information utilities like AIDA64 and CPU-Z, giving users a false impression that the phones are running Android 14 and have improved hardware.

The malicious Android apps are created using an open-source project called LSPatch that allows the trojan, dubbed Shibai, to be injected into otherwise legitimate software. In total, about 40 different applications, like messengers and QR code scanners, are estimated to have been modified in this manner.

In the artifacts analyzed by Doctor Web, the application hijacks the app update process to retrieve an APK file from a server under the attacker’s control and searches for strings in chat conversations that match cryptocurrency wallet address patterns associated with Ethereum or Tron. If found, they are replaced with the adversary’s addresses to reroute transactions.

“In the case of an outgoing message, the compromised device displays the correct address of the victim’s own wallet, while the recipient of the message is shown the address of the fraudsters’ wallet,” Doctor Web said.

“And when an incoming message is received, the sender sees the address of their own wallet; meanwhile, on the victim’s device, the incoming address is replaced with the address of the hackers’ wallet.”

Besides changing the wallet addresses, the malware is also fitted with capabilities to harvest device information, all WhatsApp messages, and .jpg, .png, and .jpeg images from DCIM, Pictures, Alarms, Downloads, Documents, and Screenshots folders to the attacker’s server.

The intention behind this step is to scan the stored images for wallet recovery (aka mnemonic) phrases, allowing the threat actors to gain unauthorized access to victims’ wallets and drain the assets.

It’s not clear who is behind the campaign, although the attackers have been found to leverage about 30 domains to distribute the malicious applications and employ more than 60 command-and-control (C2) servers to manage the operation.

Cybersecurity

Further analysis of the nearly two dozen cryptocurrency wallets used by the threat actors has revealed that they have received more than $1.6 million over the last two years, indicating that the supply chain compromise has paid off in a big way.

The development comes as Swiss cybersecurity company PRODAFT uncovered a new Android malware family dubbed Gorilla that’s designed to collect sensitive information (e.g., device model, phone numbers, Android version, SIM card details, and installed apps), main persistent access to infected devices, and receive commands from a remote server.

“Written in Kotlin, it primarily focuses on SMS interception and persistent communication with its command-and-control (C2) server,” the company said in an analysis. “Unlike many advanced malware strains, Gorilla does not yet employ obfuscation techniques, indicating that it may still be under active development.”

In recent months, Android apps embedding the FakeApp trojan propagated via Google Play Store have also been found making use of a DNS server to retrieve a configuration that contains a URL to be loaded.

These apps, since removed from the marketplace, impersonate well-known and popular games and apps and come fitted with the ability to receive external commands that can perform various malicious actions like loading unwanted websites or serving phishing windows.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleU.S. Govt. Funding for MITRE’s CVE Ends April 16, Cybersecurity Community on Alert
Next Article Sony’s Soneium taps EigenLayer to cut finality to under 10 seconds
Harish
  • Website
  • X (Twitter)

Related Posts

New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora

May 31, 2025

U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation

May 31, 2025

Rust-Based EDDIESTEALER Malware Uses ClickFix CAPTCHA Trick to Steal Browser Data

May 30, 2025

China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil

May 30, 2025

A Healthcare CISO’s Journey to Enabling Modern Care

May 30, 2025

U.S. Sanctions Funnull for $200M Romance Baiting Scams Tied to Crypto Fraud

May 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

NAACP calls on Memphis officials to halt operations at xAI’s ‘dirty data center’

May 31, 2025

Meta plans to automate many of its product risk assessments

May 31, 2025

Legends Struggles in Box Office Bow, Lilo & Stitch No. 1

May 31, 2025

BitMEX discovers cybersecurity lapses in North Korea hacker group

May 31, 2025
Don't Miss
Blockchain

BitMEX discovers cybersecurity lapses in North Korea hacker group

May 31, 20253 Mins Read

The BitMEX crypto exchange’s security team discovered gaps in the operational security of the Lazarus…

Insurers Race to Cover Crypto Kidnap and Ransom Risks

May 31, 2025

FTX Bankruptcy Estate distributes $5 billion

May 30, 2025

MEXC detects 200% surge in fraud during Q1

May 30, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

NAACP calls on Memphis officials to halt operations at xAI’s ‘dirty data center’

May 31, 2025

Meta plans to automate many of its product risk assessments

May 31, 2025

TC Sessions: AI Trivia Countdown — Your next shot at winning big

May 31, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.