Hackers Are Taking Advantage of Typing Mistakes to Steal Cryptocurrency – Security Bitcoin News – Bitcoin News

by Sergio Goschenko
A group of hackers have taken advantage of typing mistakes in order to introduce malware to Android phones and Windows-based PCs. Using a technique called typosquatting, which consists of registering domains that are dramatically near to the ones of official brands of organizations, hackers are getting data and private keys from unsuspected users, according to a report issued by Cyble.
Hackers have set up a net of malware-infected domains that take advantage of the typing inaccuracies of users when getting to a determined website. According to a report issued by Cyble, a cyber security and digital risk assessment firm, these domains mimic renowned organizations and apps, like the Google Play Store, Apkure, and Apkcombo, among others.
Users that visit the domains are prompted to download an infected version of the app requested, which will serve as a vehicle for the infection. The target device, be it an Android phone or a Windows PC, will then be infected with a version of ERMAC, a malware trojan that allows the threat actors to access several critical private data in the targeted device, including private keys.
The banking trojan was first discovered in 2021 and it is now targeting more than 460 applications, allowing attackers to rent its services for $5,000 a month.
While the mentioned report only found evidence of a little group of apps and brands being mimicked, further investigation by another security source confirmed that at least 27 brands and app names are being targeted by this kind of attack. Among these are Tiktok
Vidmate, Snapchat, Paypal, and even more dev-focused apps like Notepad+ and the Tor Browser.
Cryptocurrency wallets and crypto mining and related sites are also on the list. Tronlink
Metamask, Phantom, Cosmos Wallet, and Ethermine are part of the group of sites also targeted. Each one of these fake domains has different typo-squatted domains registered, to maximize the effect and damage of the attack.
Cybel makes different recommendations to avoid this kind of attack, including having an effective antivirus protecting your phone and PC, and monitoring your wallets and banking accounts regularly. However, the best advice is to arrive at the web pages of software and apps through the use of a search engine, avoiding blog-posted directions and links shown as part of advertisement campaigns.
What do you think about hackers taking advantage of misspelled domain names to steal crypto? Tell us in the comments section below.
Sergio is a cryptocurrency journalist based in Venezuela. He describes himself as late to the game, entering the cryptosphere when the price rise happened during December 2017. Having a computer engineering background, living in Venezuela, and being impacted by the cryptocurrency boom at a social level, he offers a different point of view about crypto success and how it helps the unbanked and underserved.

Image Credits: Shutterstock, Pixabay, Wiki Commons
Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article.
Following a Brief Fee Spike, Gas Prices to Move Ethereum Drop 76% in 12 Days
Transaction fees on the Ethereum network are dropping again after average fees saw a brief spike on April 5 jumping to $43 per transfer. 12 days later, average ether fees are close to dropping below $10 per transaction and median-sized … read more.
Ripple CEO: SEC Lawsuit Over XRP ‘Has Gone Exceedingly Well’
The CEO of Ripple Labs says that the lawsuit brought by the U.S. Securities and Exchange Commission (SEC) against him and his company over XRP “has gone exceedingly well.” He stressed: “This case is important, not just for Ripple, it’s … read more.

Check all the news here

source

Post expires at 10:22am on Wednesday April 26th, 2023

Leave a Reply

Next Post

The Future of Digital Banking in North America: Chain reactions - Cryptocurrency vs. remittances - Finextra

Wed Oct 26 , 2022
Welcome to Finextra. We use cookies to help us to deliver our services. We’ll assume you’re ok with this, but you may change your preferences at our Cookie Centre. Please read our Privacy Policy.For Finextra’s free daily newsletter, breaking news and flashes and weekly job board.Madhvi MavadiyaHead of Content, FinextraThis is […]
%d bloggers like this: