Surge of Crypto-Theft via Fake WhatsApp and Telegram Apps on Android Phones

Listen to this Post

In June 2024, a startling discovery by Doctor Web researchers revealed an alarming trend: cheap Android phones preloaded with counterfeit WhatsApp and Telegram apps designed to siphon off cryptocurrency. This type of malware attack, known as “clipping,” has gained traction, specifically targeting lower-end smartphones that imitate well-known brands. The attackers have managed to infiltrate the supply chains of Chinese smartphone manufacturers, embedding malicious apps during production. This campaign has raised serious concerns about the security of budget Android devices, and it’s become evident that cybercriminals are innovating at an unsettling pace.

Summary

Researchers uncovered a malicious operation where attackers were embedding malware in Android phones right at the manufacturing level. These phones, which closely resembled popular models like the Samsung Galaxy S23 Ultra and the Xiaomi Note 13 Pro, were in fact low-end models with altered system information to trick users and apps. These devices were mostly running Android 12, disguised as Android 14 to deceive buyers into thinking they were getting newer, more powerful devices.

The fake WhatsApp and Telegram apps were infected with a trojan named Shibai. This trojan had the ability to hijack cryptocurrency wallet addresses from users’ messages and replace them with the attackers’ own. It also had an alarming ability to scan device storage for wallet recovery phrases saved as images, thereby enabling full crypto theft. Additionally, the malware could exfiltrate chat data and even use backup wallet addresses in case the command-and-control (C2) server was unreachable.

Over the course of its existence, this attack has spread to over 60 C2 servers and 30 domains, making it a widespread threat to mobile security. One wallet reportedly earned over $1 million in cryptocurrency in just two years, while others earned substantial sums as well. Despite the attackers’ ability to change wallets frequently, this scam has already proven to be quite profitable.

What Undercode Says:

The implications of this attack are far-reaching. For one, it highlights a growing problem in the Android ecosystem: the vulnerability of budget devices. These phones, often marketed at very attractive price points, can be a haven for hackers who manage to sneak malicious code into the supply chain. The practice of spoofing device specs—such as falsely claiming the phone runs Android 14—gives attackers an added layer of obfuscation, making it harder for users and even security apps to detect the real risks.

The fact that these phones appeared to have high-end specifications while being budget models shows a disturbing trend in smartphone manufacturing, where profit margins are prioritized over security. Hackers exploiting this loophole is a serious concern, especially since these devices are usually sold with pre-installed software that could contain hidden malware. Notably, the ability to insert trojans into popular applications like WhatsApp and Telegram is especially dangerous given how widely used these apps are for financial transactions.

Moreover, the use of tools like LSPatch to alter legitimate apps such as WhatsApp and Telegram allows attackers to manipulate wallet addresses, a clear indication of a well-orchestrated and strategic attack. The Shibai trojan isn’t just about wallet address replacement; it is a complete attack tool designed to exfiltrate data, enabling the theft of crypto in multiple ways. These methods indicate a high level of sophistication in the attackers’ approach, suggesting that they are well-funded and equipped to sustain their operations.

While this campaign has been linked to Chinese manufacturers, it’s not an isolated case. A pattern of pre-installed malware has been seen in Android phones for years, with various security firms reporting incidents as far back as 2014. This history underscores a critical issue: the ongoing problem of devices coming from the factory with hidden vulnerabilities. Even global companies like Xiaomi and Huawei have been implicated in the past.

The

For end users, this campaign is a stark reminder of the importance of vigilance when purchasing smartphones—especially budget models. The advice from researchers is clear: avoid buying phones that claim to have features disproportionate to their price, as these are often red flags for hidden security risks. Furthermore, users should stick to downloading apps from trusted sources, such as the official Google Play Store or other reputable app stores like RuStore and AppGallery.

On the technical side, Dr.

Fact Checker Results

The report presented by Doctor Web aligns with known trends in the cyber threat landscape. Pre-installed malware on smartphones, especially from budget manufacturers, has been a recurring issue. The existence of trojans like Shibai and the continued evolution of clipping attacks further reinforce the reality that smartphone security, particularly in lower-end devices, is a major concern. Given the prevalence of these types of attacks, users need to stay vigilant and ensure their devices are protected through robust security measures.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.digitaltrends.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image