Over 20 Malicious Apps on Google Play Target Users for Seed Phrases

A recent investigation by threat intelligence firm Cyble has spotted a campaign targeting cryptocurrency users through the Google Play Store with more than 20 malicious Android applications.

These apps, disguised as trusted crypto wallets like SushiSwap, PancakeSwap, Hyperliquid, and Raydium, have been found harvesting users’ 12-word mnemonic phrases, the keys that unlock their crypto funds.

These apps mimic legitimate wallet interfaces, luring users into entering sensitive recovery phrases. Once entered, the attackers can access the real wallets and empty them. While Google has removed many of these fake apps following Cyble’s report, a handful remain live on the store and have been flagged for removal.

How the Scam Works

According to Cyble’s report shared with Hackread.com, the fraudulent apps carry names and icons of well-known crypto platforms and appear under developer accounts that previously hosted genuine apps, including games, video downloaders, and streaming tools. These accounts, some with more than 100,000 downloads, appear to have been hijacked and repurposed to distribute the malicious apps.

Over 20 Malicious Apps on Google Play Target Users for Seed Phrases
Screenshot showing a developer account that previously published legitimate apps, now used for malicious activity (Credit: Cyble)

In several cases, the apps use a development tool known as the “Median framework” to quickly turn phishing websites into Android apps. The apps load these phishing pages directly inside a WebView, an embedded browser window, that asks users for their mnemonic phrase under the guise of wallet access.

The campaign isn’t only widespread in scale but also coordinated in its infrastructure. One phishing domain found by Cyble was linked to over 50 similar domains, all part of the same broader effort to compromise wallet security.

Cyble’s researchers also noticed a pattern in how these fake apps operate. Many of them include links in their privacy policies that actually lead to phishing websites designed to steal users’ wallet recovery phrases. The apps also tend to follow similar naming styles, which points to the use of automated tools to quickly create and publish them.

On top of that, several apps are connected to the same servers or websites, showing they’re part of a larger, organized effort. Some of the fake domains linked to these apps include:

  • bullxnisbs
  • hyperliqwsbs
  • raydifloydcz
  • sushijamessbs
  • pancakefentfloydcz

These domains impersonate various wallet providers and serve pages meant to trick users into handing over their seed phrases. Meanwhile, the partial list of malicious apps, courtesy of Cyble, is available below:

  1. Raydium
  2. SushiSwap
  3. Suiet Wallet
  4. Hyperliquid
  5. BullX Crypto
  6. Pancake Swap
  7. Meteora Exchange
  8. OpenOcean Exchange
  9. Harvest Finance Blog

Despite efforts to remove the apps, the campaign is ongoing. As of this report, a few remain active on the Play Store. The quick replication of these apps using off-the-shelf frameworks suggests the attackers could easily spin up more fake apps if not quickly blocked.

This poses a serious risk. Unlike traditional banking, there is no safety net for crypto theft. Once a wallet is drained, the funds are nearly impossible to recover.

Cyble has shared detailed indicators of compromise (IOCs) including app names, package identifiers, and phishing domains, which security professionals can use to block or investigate further.

This campaign goes on to show how attackers continue to target the already vulnerable crypto space through official channels like app stores. While app platforms are working to catch malicious uploads, users remain on the receiving end of these cybersecurity threats. Therefore, users are urged to watch out and follow these steps to protect themselves:

Watch for red flags like low review counts, recently republished apps, or links to strange domains in privacy policies.

  • Avoid downloading and installing unnecessary apps.
  • Enable Google Play Protect to help identify potentially harmful apps.
  • Use biometric security and two-factor authentication where available.
  • Always watch out while downloading apps from third-party as well as official stores.
  • Never enter your 12-word phrase into any app or website unless you’re certain it’s legitimate.



Source link

Visited 1 times, 1 visit(s) today

Related Article

Google AI Studio users concerned about free access

Earlier this week, Google doubled the recently introduced 2.5 Pro query limit in the Gemini app for AI Pro subscribers. It then emerged that Google is planning to make similar limit changes to AI Studio. Google AI Studio is a developer tool that lets you directly access Gemini and other first-party models. To date, the

Which Automakers Will Lead World EV Market In 2025, 2026, & 2027?

Last Updated on: 7th June 2025, 03:33 pm The electric vehicle market is growing fast, and it’s also changing fast. As always, I’m curious what the market will become in the future. However, with so much changing, I’m not just curious about how the market will look in 5 to 10 years; I’m curious how

6 Samsung user benefits with Microsoft apps and services

Google already has its own self-contained workspace ecosystem, which Samsung always had a choice to set up and use. Aside from Google, Samsung has consistently maintained a strong relationship with Microsoft. Having your Samsung account sync to Microsoft services can elevate your productivity on various levels. As a Samsung user, you can easily integrate your

Delete Every App On Your Smartphone That’s On This List

All these apps are dangerous getty You probably have at least 100 apps on your phone — likely more. And there’s plenty of choice, almost 2 million apps on Apple’s App Store and nearer 3 million on Google’s Play Store. You’re urged only to install apps from official stores, but sometimes even that doesn’t keep

These two apps finally fixed my creative workflow

Dhruv Bhutani / Android Authority For years, Notion has been my go-to for organizing everything from invoices to movie watchlists. Its flexibility as a database is unmatched, but when it came to creative workflows like jotting down spontaneous ideas, threading together thoughts, and collecting visual inspiration, that’s where Notion starts to feel a bit rigid.

Vietnamese automaker VinFast bets big on India’s fledgling EV market

The VF7 (in picture) and VF6 models will be manufactured at VinFast’s plant in Thoothukudi, Tamil Nadu. | Photo Credit: Special arrangement VinFast, the first automaker from Vietnam to expand into the global market, is set to make inroads into the Indian EV space with production at its plant in Tamil Nadu’s Thoothukudi district set

Electric Vehicles for Construction, Agriculture and Mining

Electric Vehicles for Construction, Agriculture and Mining (EV-CAM) Market HTF MI just released the Global Electric Vehicles for Construction, Agriculture and Mining (EV-CAM) Market Study, a comprehensive analysis of the market that spans more than 143+ pages and describes the product and industry scope as well as the market prognosis and status for 2025-2032. The

0
Would love your thoughts, please comment.x
()
x