Skip to main content

Hackers Are Taking Advantage of Typing Mistakes to Steal Cryptocurrency

hackers Security

A group of hackers have taken advantage of typing mistakes in order to introduce malware to Android phones and Windows-based PCs. Using a technique called typosquatting, which consists of registering domains that are dramatically near to the ones of official brands of organizations, hackers are getting data and private keys from unsuspected users, according to a report issued by Cyble.

Typing a Web Domain Incorrectly Might Be Dangerous for Your Wallet

Hackers have set up a net of malware-infected domains that take advantage of the typing inaccuracies of users when getting to a determined website. According to a report issued by Cyble, a cyber security and digital risk assessment firm, these domains mimic renowned organizations and apps, like the Google Play Store, Apkure, and Apkcombo, among others.

Users that visit the domains are prompted to download an infected version of the app requested, which will serve as a vehicle for the infection. The target device, be it an Android phone or a Windows PC, will then be infected with a version of ERMAC, a malware trojan that allows the threat actors to access several critical private data in the targeted device, including private keys.

The banking trojan was first discovered in 2021 and it is now targeting more than 460 applications, allowing attackers to rent its services for $5,000 a month.

Hackers Targeting More Sites and Brands Involved

While the mentioned report only found evidence of a little group of apps and brands being mimicked, further investigation by another security source confirmed that at least 27 brands and app names are being targeted by this kind of attack. Among these are Tiktok
Vidmate, Snapchat, Paypal, and even more dev-focused apps like Notepad+ and the Tor Browser.

Cryptocurrency wallets and crypto mining and related sites are also on the list. Tronlink
Metamask, Phantom, Cosmos Wallet, and Ethermine are part of the group of sites also targeted. Each one of these fake domains has different typo-squatted domains registered, to maximize the effect and damage of the attack.

Cybel makes different recommendations to avoid this kind of attack, including having an effective antivirus protecting your phone and PC, and monitoring your wallets and banking accounts regularly. However, the best advice is to arrive at the web pages of software and apps through the use of a search engine, avoiding blog-posted directions and links shown as part of advertisement campaigns.

What do you think about hackers taking advantage of misspelled domain names to steal crypto? Tell us in the comments section below.



from Bitcoin News https://ift.tt/hYcm7dU

Comments

Popular posts from this blog

Deep Web Roundup: Dream Adds Monero and Bitcoin Tumbler “Chip Mixer” Launches

The darknet has been quiet of late, which is the way it’s meant to be. No news means no mega busts, honeypots, or mass market shutdowns. Even when it’s out of the spotlight though, the deep web is quietly making news, whether trialling the latest privacy coins or the newest coin mixers that promise to restore a little of the privacy that’s being stripped away from bitcoin users on a daily basis. Also read: U.S. Agency ICE Conducts Investigations That Exploit Blockchain Activity The Battle for Privacy Heats Up Privacy is all relative, but of late there’s been relatively little privacy to be enjoyed by bitcoin users. Blockchain monitoring software is becoming more sophisticated and more common, with U.S. law enforcement agencies using it to profile and hunt down deep web users. Chip Mixer is a relatively new bitcoin tumbler that’s designed to restore some of that privacy. Available on both the clearnet and darknet, the service uses a variety of techniques to obfuscate blockchain m...

International Crypto Exchange Luno Adds Bitcoin Cash Trading

Luno exchange has added bitcoin cash trading to the platform following feedback from its client base. BCH is now only the third cryptocurrency available for trading on the exchange, in addition to BTC and ETH , but more options could be on the way once Luno determines that they are credible enough. Also Read: Bitflyer Adds Bitcoin Cash Trading Across Europe and the US Luno Adds Bitcoin Cash Trading Luno, the London-headquartered company formerly known as Bitx, recently announced that bitcoin cash was made available on its cryptocurrency exchange. Starting from Monday, September 23, customers at Luno are now able to store, buy and sell BCH on the platform. The reason given for adding BCH to the exchange is feedback from users in developing markets that convinced Luno to expand their offering from previously just BTC and ETH . Marcus Swanepoel, CEO of Luno, said , “We are in a new and exciting financial era. Developing economies are leading the large-scale adoption and appli...

Seven UK Companies Form Cryptocurrency Trade Body

Seven major crypto companies operating in the UK have announced the formation an independent cryptocurrency trade body. The group, Crypto UK, has stated that its principal aim is to “improve industry standards and engage policymakers.” Also Read:   Independent Ratings Agency Alerts Investors About Dangers of Tether Leading Cryptocurrency Companies form Crypto UK Trade Body Seven leading cryptocurrency companies operating the UK have formed an independent trade body tasked with developing self-regulatory standards for the cryptocurrency industry, in addition to “engag[ing] policymakers.” The members of Crypto UK are Coinbase, Etoro, Cex.io, Blockex, Commerceblock, Coinshares, and Cryptocompare – comprising trading platforms, exchanges, asset managers, merchants, comparison websites, and intermediaries from the cryptocurrency sector. “Regulation is Imminent” The Crypto UK chairman and managing director of Etoro, Iqbal Gandham, described the trade body’s mission as “promot[in...