Skip to main content

Hackers Are Taking Advantage of Typing Mistakes to Steal Cryptocurrency

hackers Security

A group of hackers have taken advantage of typing mistakes in order to introduce malware to Android phones and Windows-based PCs. Using a technique called typosquatting, which consists of registering domains that are dramatically near to the ones of official brands of organizations, hackers are getting data and private keys from unsuspected users, according to a report issued by Cyble.

Typing a Web Domain Incorrectly Might Be Dangerous for Your Wallet

Hackers have set up a net of malware-infected domains that take advantage of the typing inaccuracies of users when getting to a determined website. According to a report issued by Cyble, a cyber security and digital risk assessment firm, these domains mimic renowned organizations and apps, like the Google Play Store, Apkure, and Apkcombo, among others.

Users that visit the domains are prompted to download an infected version of the app requested, which will serve as a vehicle for the infection. The target device, be it an Android phone or a Windows PC, will then be infected with a version of ERMAC, a malware trojan that allows the threat actors to access several critical private data in the targeted device, including private keys.

The banking trojan was first discovered in 2021 and it is now targeting more than 460 applications, allowing attackers to rent its services for $5,000 a month.

Hackers Targeting More Sites and Brands Involved

While the mentioned report only found evidence of a little group of apps and brands being mimicked, further investigation by another security source confirmed that at least 27 brands and app names are being targeted by this kind of attack. Among these are Tiktok
Vidmate, Snapchat, Paypal, and even more dev-focused apps like Notepad+ and the Tor Browser.

Cryptocurrency wallets and crypto mining and related sites are also on the list. Tronlink
Metamask, Phantom, Cosmos Wallet, and Ethermine are part of the group of sites also targeted. Each one of these fake domains has different typo-squatted domains registered, to maximize the effect and damage of the attack.

Cybel makes different recommendations to avoid this kind of attack, including having an effective antivirus protecting your phone and PC, and monitoring your wallets and banking accounts regularly. However, the best advice is to arrive at the web pages of software and apps through the use of a search engine, avoiding blog-posted directions and links shown as part of advertisement campaigns.

What do you think about hackers taking advantage of misspelled domain names to steal crypto? Tell us in the comments section below.



from Bitcoin News https://ift.tt/hYcm7dU

Comments

Popular posts from this blog

Mt Gox Creditors Updated, Trustee Says Rehabilitation Custodian Is ‘Currently Preparing to Make Repayments’

On August 31, 2022, the Mt Gox trustee Nobuaki Kobayashi explained in a recent letter that the rehabilitation custodian is “currently preparing to make repayments” to Mt Gox creditors. Trustee Updates Mt Gox Creditors — Repayment Date and Exchange Still Unknown Last week speculation and rumors concerning the release of 140K bitcoin ( BTC ) from Mt Gox littered social media platforms and headlines. Bitcoin.com News covered the situation six days ago as a number of people and Mt Gox creditors called the rumors “ fake news .” During that same period of time, a bitcoin whale transferred 10,000 BTC to unknown wallets, and a 2018 annotation , heuristics, and clustering methods show the funds likely originated from the June 2011 Mt Gox hacks. Following the mysterious whale transfer, last Wednesday, Mt Gox published an official update from the court trustee Nobuaki Kobayashi that explains the court is “currently preparing to make repayments” to creditors. Mt Gox creditors have been wait...

Fidelity Discusses Bitcoin as Portfolio Insurance — Could Soon Stand in ‘Stark Contrast’ to Path Fiat Currencies Take

Fidelity Digital Assets, a subsidiary of Fidelity Investments, says that bitcoin could be considered portfolio insurance. The firm notes that the cryptocurrency “may soon stand in stark contrast to the path that the rest of the world and fiat currencies may take — namely the path of increased supply, additional currency creation, and central bank balance sheet expansion.” Fidelity Says Bitcoin Could Be Portfolio Insurance Fidelity Digital Assets, a subsidiary of Fidelity Investments, recently published a research study titled “The Rising Dollar and Bitcoin.” The research outlines “how bitcoin could be considered portfolio insurance” as the rising dollar impacts global currency markets. “The strengthening U.S. dollar is wreaking havoc among other countries and may put pressure on the Federal Reserve to soon reverse its tightening monetary actions, something that has precedent based on 1985’s Plaza Accord,” Fidelity explained. In addition, “more monetary debasement may be needed to ...

Economists Discuss Russia, China Potentially Developing Gold-Backed Currency That Could Undermine US Dollar

Economists have weighed in on reports that China and Russia may be developing a new gold-backed currency that could undermine the U.S. dollar’s status as the world’s primary reserve currency. Russia and China May Be Developing Gold-Backed Currency Several experts have shared their views on Russia and China potentially creating a new gold-baked currency, Fox Business reported Saturday, emphasizing that China has been buying up huge quantities of gold while Russia was forced off the U.S. dollar due to sanctions imposed on the country following its invasion of Ukraine. The news outlet noted that some experts have cautioned that these moves, along with the closer relationship that has developed between Moscow and Beijing, point to the likelihood of China attempting to launch a gold-backed currency. However, neither Russia nor China has officially confirmed plans for such a currency. Craig Singleton, senior fellow at the Foundation for Defense of Democracies and a former U.S. diplomat,...