Over 20 Malicious Apps on Google Play Target Users for Seed Phrases

A recent investigation by threat intelligence firm Cyble has spotted a campaign targeting cryptocurrency users through the Google Play Store with more than 20 malicious Android applications.

These apps, disguised as trusted crypto wallets like SushiSwap, PancakeSwap, Hyperliquid, and Raydium, have been found harvesting users’ 12-word mnemonic phrases, the keys that unlock their crypto funds.

These apps mimic legitimate wallet interfaces, luring users into entering sensitive recovery phrases. Once entered, the attackers can access the real wallets and empty them. While Google has removed many of these fake apps following Cyble’s report, a handful remain live on the store and have been flagged for removal.

How the Scam Works

According to Cyble’s report shared with Hackread.com, the fraudulent apps carry names and icons of well-known crypto platforms and appear under developer accounts that previously hosted genuine apps, including games, video downloaders, and streaming tools. These accounts, some with more than 100,000 downloads, appear to have been hijacked and repurposed to distribute the malicious apps.

Over 20 Malicious Apps on Google Play Target Users for Seed Phrases
Screenshot showing a developer account that previously published legitimate apps, now used for malicious activity (Credit: Cyble)

In several cases, the apps use a development tool known as the “Median framework” to quickly turn phishing websites into Android apps. The apps load these phishing pages directly inside a WebView, an embedded browser window, that asks users for their mnemonic phrase under the guise of wallet access.

The campaign isn’t only widespread in scale but also coordinated in its infrastructure. One phishing domain found by Cyble was linked to over 50 similar domains, all part of the same broader effort to compromise wallet security.

Cyble’s researchers also noticed a pattern in how these fake apps operate. Many of them include links in their privacy policies that actually lead to phishing websites designed to steal users’ wallet recovery phrases. The apps also tend to follow similar naming styles, which points to the use of automated tools to quickly create and publish them.

On top of that, several apps are connected to the same servers or websites, showing they’re part of a larger, organized effort. Some of the fake domains linked to these apps include:

  • bullxnisbs
  • hyperliqwsbs
  • raydifloydcz
  • sushijamessbs
  • pancakefentfloydcz

These domains impersonate various wallet providers and serve pages meant to trick users into handing over their seed phrases. Meanwhile, the partial list of malicious apps, courtesy of Cyble, is available below:

  1. Raydium
  2. SushiSwap
  3. Suiet Wallet
  4. Hyperliquid
  5. BullX Crypto
  6. Pancake Swap
  7. Meteora Exchange
  8. OpenOcean Exchange
  9. Harvest Finance Blog

Despite efforts to remove the apps, the campaign is ongoing. As of this report, a few remain active on the Play Store. The quick replication of these apps using off-the-shelf frameworks suggests the attackers could easily spin up more fake apps if not quickly blocked.

This poses a serious risk. Unlike traditional banking, there is no safety net for crypto theft. Once a wallet is drained, the funds are nearly impossible to recover.

Cyble has shared detailed indicators of compromise (IOCs) including app names, package identifiers, and phishing domains, which security professionals can use to block or investigate further.

This campaign goes on to show how attackers continue to target the already vulnerable crypto space through official channels like app stores. While app platforms are working to catch malicious uploads, users remain on the receiving end of these cybersecurity threats. Therefore, users are urged to watch out and follow these steps to protect themselves:

Watch for red flags like low review counts, recently republished apps, or links to strange domains in privacy policies.

  • Avoid downloading and installing unnecessary apps.
  • Enable Google Play Protect to help identify potentially harmful apps.
  • Use biometric security and two-factor authentication where available.
  • Always watch out while downloading apps from third-party as well as official stores.
  • Never enter your 12-word phrase into any app or website unless you’re certain it’s legitimate.



Source link

Visited 1 times, 1 visit(s) today

Related Article

Leaked Signal messages that allegedly shared military information bring more ‘bad news’ for US Defence Secretary Pete Hegseth

Defence Secretary Pete Hegseth (Image credit: AP) The Pentagon’s watchdog is investigating whether aides to US Defence Secretary Pete Hegseth were asked to delete Signal messages that may have shared sensitive military information with a reporter. This inquiry focuses on how information about the March 15 airstrikes on Houthi targets in Yemen was disseminated through

Defenchick, Doom & Destiny Worlds, and more

Before we all head off into the weekend to enjoy our time with Switch 2 (or wait anxiously for one to arrive), we are going to take a look at all of Friday’s best deals on Android games and apps. Alongside the Google Play offers, we are also still tracking Galaxy Tab S10 Ultra at

Electric Vehicle Battery Pack Modules Market to Reach USD 85.8

The global battery pack modules market for electric vehicles (EVs) is set for extraordinary growth, propelled by the escalating demand for eco-friendly transportation and the continuous drive toward more efficient, cost-effective battery solutions. Valued at US$ 23.1 Bn in 2022, the market is projected to expand at a robust CAGR of 15.7% from 2023 to

EV Battery Market Is Going to Boom

EV Battery Market HTF MI just released the Global EV Battery Market Study, a comprehensive analysis of the market that spans more than 143+ pages and describes the product and industry scope as well as the market prognosis and status for 2025-2032. The marketization process is being accelerated by the market study’s segmentation by important

Mobile Phone Accessories Market to Reach US$333.9 Bn by 2031

Mobile Phone Accessories Market ✅Market to Expand at 7.9% CAGR Fueled by Premiumization and Online Sales Surge According to the latest study by Persistence Market Research, the global mobile phone accessories market is projected to rise significantly from US$196.1 Bn in 2024 to US$333.9 Bn by 2031, registering a healthy CAGR of 7.9%. The market’s

Nissan’s new EV now going global after securing record orders in China

Good news for the North American market and the rest of the world because the Nissan N7 EV – Nissan’s new EV that’s absolutely smashing it in China – is going global. Originally unveiled for the Chinese market, the N7 did better than expected. So, essentially, it is going global by popular demand. Only two

0
Would love your thoughts, please comment.x
()
x