Over 20 Malicious Apps on Google Play Target Users for Seed Phrases

A recent investigation by threat intelligence firm Cyble has spotted a campaign targeting cryptocurrency users through the Google Play Store with more than 20 malicious Android applications.

These apps, disguised as trusted crypto wallets like SushiSwap, PancakeSwap, Hyperliquid, and Raydium, have been found harvesting users’ 12-word mnemonic phrases, the keys that unlock their crypto funds.

These apps mimic legitimate wallet interfaces, luring users into entering sensitive recovery phrases. Once entered, the attackers can access the real wallets and empty them. While Google has removed many of these fake apps following Cyble’s report, a handful remain live on the store and have been flagged for removal.

How the Scam Works

According to Cyble’s report shared with Hackread.com, the fraudulent apps carry names and icons of well-known crypto platforms and appear under developer accounts that previously hosted genuine apps, including games, video downloaders, and streaming tools. These accounts, some with more than 100,000 downloads, appear to have been hijacked and repurposed to distribute the malicious apps.

Over 20 Malicious Apps on Google Play Target Users for Seed Phrases
Screenshot showing a developer account that previously published legitimate apps, now used for malicious activity (Credit: Cyble)

In several cases, the apps use a development tool known as the “Median framework” to quickly turn phishing websites into Android apps. The apps load these phishing pages directly inside a WebView, an embedded browser window, that asks users for their mnemonic phrase under the guise of wallet access.

The campaign isn’t only widespread in scale but also coordinated in its infrastructure. One phishing domain found by Cyble was linked to over 50 similar domains, all part of the same broader effort to compromise wallet security.

Cyble’s researchers also noticed a pattern in how these fake apps operate. Many of them include links in their privacy policies that actually lead to phishing websites designed to steal users’ wallet recovery phrases. The apps also tend to follow similar naming styles, which points to the use of automated tools to quickly create and publish them.

On top of that, several apps are connected to the same servers or websites, showing they’re part of a larger, organized effort. Some of the fake domains linked to these apps include:

  • bullxnisbs
  • hyperliqwsbs
  • raydifloydcz
  • sushijamessbs
  • pancakefentfloydcz

These domains impersonate various wallet providers and serve pages meant to trick users into handing over their seed phrases. Meanwhile, the partial list of malicious apps, courtesy of Cyble, is available below:

  1. Raydium
  2. SushiSwap
  3. Suiet Wallet
  4. Hyperliquid
  5. BullX Crypto
  6. Pancake Swap
  7. Meteora Exchange
  8. OpenOcean Exchange
  9. Harvest Finance Blog

Despite efforts to remove the apps, the campaign is ongoing. As of this report, a few remain active on the Play Store. The quick replication of these apps using off-the-shelf frameworks suggests the attackers could easily spin up more fake apps if not quickly blocked.

This poses a serious risk. Unlike traditional banking, there is no safety net for crypto theft. Once a wallet is drained, the funds are nearly impossible to recover.

Cyble has shared detailed indicators of compromise (IOCs) including app names, package identifiers, and phishing domains, which security professionals can use to block or investigate further.

This campaign goes on to show how attackers continue to target the already vulnerable crypto space through official channels like app stores. While app platforms are working to catch malicious uploads, users remain on the receiving end of these cybersecurity threats. Therefore, users are urged to watch out and follow these steps to protect themselves:

Watch for red flags like low review counts, recently republished apps, or links to strange domains in privacy policies.

  • Avoid downloading and installing unnecessary apps.
  • Enable Google Play Protect to help identify potentially harmful apps.
  • Use biometric security and two-factor authentication where available.
  • Always watch out while downloading apps from third-party as well as official stores.
  • Never enter your 12-word phrase into any app or website unless you’re certain it’s legitimate.



Source link

Visited 1 times, 1 visit(s) today

Related Article

EV Battery Energy Storage Market Set for Explosive Growth, CAGR

EV Battery Energy Storage Market The Battery Energy Storage System (BESS) Market for EVs is witnessing robust growth, driven by the rising adoption of electric vehicles and advancements in battery technologies. Valued at US$ 3.1 Bn in 2023, the market is projected to surge at a CAGR of 25.6%, reaching US$ 38.9 Bn by 2034.

EV Charging Networks Market Is Booming Worldwide

EV Charging Networks Market The “EV Charging Networks Market Research Report” is the result of extensive research and analysis conducted by our team of experienced market researchers. It encompasses a wide range of critical factors influencing the EV Charging Networks Market Growth from 2025 to 2032, including competitive landscape, consumer behavior, and technological advancements. This

Samsung Confirms AI Upgrade Choice—This Changes Your Phone

This decision defines the future of your phone. NurPhoto via Getty Images A timely warning from Samsung this week, which neatly sets out the biggest upgrade decision now facing Android users. As whispers start to spread suggesting a disconnect between Samsung and Google at the heart of Android, this is critical. We’re talking AI and

Electric Vehicle HVAC Market Forecast (2023-2032) : From USD

According to a new report published by Allied Market Research, titled, “Electric Vehicle HVAC Market Size, Share, Competitive Landscape and Trend Analysis Report, by Technology, by Vehicle Type, by Component : Global Opportunity Analysis and Industry Forecast, 2023-2032”. The global electric vehicle HVAC market size was valued at $4.6 billion in 2022, and is projected

Redmagic 10S Pro review: Refined and cooler than ever

At a glance Expert’s Rating Pros Excellent performance Upgraded cooling system Great battery life Dedicated gaming features Cons Some bloatware Only 3 years of software support Terrible selfie camera Our Verdict Redmagic has done it again, with a fantastic mobile gaming platform that boasts power, battery life and advanced cooling, but without the scary price

Electric Vehicle Market Growth 2025

Credits Image: https://netzeroindia.org The Global Electric Vehicle Market reached US$599.50 billion in 2024 and is expected to reach US$1,194.54 billion by 2032, growing with a CAGR of 9% during the forecast period 2025-2032. The Electric Vehicle Market, as analyzed by DataM Intelligence, offers a comprehensive industry overview backed by in-depth insights, historical trends, and key

Recycled Cobalt Market Demand in Electric Vehicle Batteries

Recycled Cobalt Market InsightAce Analytic Pvt. Ltd. announces the release of a market assessment report on the ” Recycled Cobalt Market- (By recycling technology (Direct Recycling, Hydrometallurgical Processes, Pyrometallurgical Processes, Mechanical Processes), by source (End-of-Life Batteries, Electronics Waste, Mining and Refining), by application (Electric Vehicle Batteries, Aerospace and Defense Alloys, Consumer Electronics, Energy Storage Systems),

0
Would love your thoughts, please comment.x
()
x