Fraudulent trading apps have emerged as a significant threat to users in cyberspace. As these applications target and lure victims via lucrative ads on different “social media” and “messaging platforms.”
While all these scams promise high returns to users on their investments in reality, they lead to ‘huge financial losses’ to those who download the apps and invest their money.
Cybersecurity analysts at Group-IB recently warned of fraudulent trading apps from Apple and Google Play Store that steal login credentials.
Since May 2024 researchers identified sophisticated cyber fraud operations involving fake trading apps on both major platforms “Android” and “iOS.”
Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free
It’s been identified that these apps have been using a cross-platform development framework called “UniApp” with “Vue.js” technology.
These applications were distributed through the “Google Play Store,” “Apple App Store,” and “phishing websites.”
While all these are part of a scam that has been dubbed “pig butchering” where threat actors employ social engineering tactics via “dating apps” and “social media” platforms to exploit victims.
The technical architecture involves “WebSocket” connections for app-based trading and “HTTPS” for web browser access.
However, the apps themselves use “HTML5 WebView” to display web-based content.
To evade Apple’s security checks the iOS version offers evasion techniques (time-based trigger), and for sideloaded versions, it also requires “enterprise certificate trust enablement.”
The malicious applications masquerade as “mathematical formula calculators,” “implement a multi-step fraud process requiring invitation codes,” “identity verification (ID/passport uploads),” and “personal information collection.”
Unlike traditional banking trojans (GoldPickaxe, which was discovered in February 2024), these apps don’t contain explicit malicious code but rather serve as sophisticated deceptions, reads the Group-IB report.
They do so by using “TermsFeed” for legitimate-appearing legal agreements and supporting multiple languages like ‘English,’ ‘Portuguese,’ ‘Chinese,’ and ‘Hindi.’
This enables threat actors to “manipulate victims” into making significant deposits before preventing withdrawals.
Here the malware infrastructure operated through multiple domains, with “api.fxbrokers[.]cc” serving as the primary C2 server.
A notable discovery was the “com.ubsarov.ubsarovfx” package which is linked to the broader “UOBE FX” scam campaign.
The technical architecture utilized “web-based interfaces” to evade detection. The threat actors impersonated numerous legitimate trading platforms (FINANS INSIGHTS, Coinbase, and XTB, among others).
The sophistication of the scam lies in its ability to display real-time stock-related news and market data which creates a fake legitimate-looking environment.
After victims made investments via these fraudulent platforms the threat actors implement “withdrawal restrictions” to block and trap the users’ funds.
The infrastructure extended to domains like “gold-blockhain[.]cc,” this illustrates the extensive network and sophisticated domain registration patterns of the scam that are designed to “mimic legitimate financial institutions.”
Here below we have mentioned all the recommendations:-
Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…