Latest

Sophisticated Cryptocurrency Theft Scheme using Trojans in Telegram and WhatsApp

ESET’s team of researchers have uncovered a complex scheme designed to steal cryptocurrencies via Trojans embedded in messaging apps like Telegram and WhatsApp.

These malicious Trojans are able to replace cryptocurrency wallet addresses in chat messages with the attacker’s own address, effectively redirecting the victim’s funds.

The attackers lure users to their fake sites through Google Ads placed on scam YouTube channels. ESET has already reported fraudulent YouTube ads and channels to Google, which has blocked them.

One particularly sophisticated Trojan was found to track Telegram messages for certain keywords related to cryptocurrencies, and upon detecting one, would send a message to the attacker’s server.

Analysts believe the scammers are targeting Chinese-speaking users who use VPNs to access social networks like Telegram and WhatsApp that are blocked in China.

The ESET team also discovered Trojan versions of the messaging apps for Windows. Additionally, they found that since May 2021, dozens of mobile apps used a trojanized wallet program for Android and iOS platforms to steal cryptocurrency.

The malicious code injected into legitimate apps was difficult to detect and fully retained the original app’s functionality.

These findings highlight the importance of being cautious when using messaging and other apps, especially when dealing with sensitive information like cryptocurrencies.