Connect with us

Crypto

7 fake cryptocurrency investment apps discovered in Google Play, Apple App Store – Help Net Security

Published

on

7 fake cryptocurrency investment apps discovered in Google Play, Apple App Store – Help Net Security

Sophos released new findings on CryptoRom scams—a subset of pig butchering schemes designed to trick users of dating apps into making fake cryptocurrency investments. Since May, Sophos X-Ops has observed CryptoRom fraudsters refining their techniques, including adding an AI chat tool, like ChatGPT, to their toolset. Scammers also expanded their coercion tactics by telling victims their crypto accounts were hacked and more upfront money is needed.

Researchers additionally discovered that scammers could sneak seven new fake cryptocurrency investment apps into the official Apple App and Google Play stores, upping the potential for victims.

Investment fraud on the rise

In 2022, investment fraud caused the highest losses of any scam reported by the public to the FBI’s IC3, totaling $3.31 billion. Frauds involving cryptocurrency, including pig butchering, represented most of these scams, increasing 183% from 2021 to $2.57 billion in reported losses last year.

Researchers first learned of CryptoRom scammers using the AI chat tool — most likely ChatGPT — when a conned victim contacted the team. After contacting the victim on Tandem, a language-sharing app that has also been used as a dating app, the scammer convinced the victim to move their conversation to WhatsApp. The victim became suspicious after he received a lengthy message that was partly written by an AI chat tool using a large language model (LLM).

ChatGPT

Since OpenAI announced the release of ChatGPT, there has been broad speculation that cybercriminals may use the program for their own malicious activities. We can now say that, at least in the case of pig butchering scams, this is happening,” said Sean Gallagher, principal threat researcher, Sophos.

Advertisement

“One of the main challenges for fraudsters with CryptoRom scams is carrying out convincing, sustained conversations of a romantic nature with targets; these conversations are mostly written by ‘keyboarders,’ who are primarily based out of Asia and have a language barrier. Using something like ChatGPT can be a more efficient and effective way to keep these conversations going, making the scams less labor-intensive and more authentic. It also enables keyboarders to simultaneously engage with multiple victims at one time,” Gallagher added.

Extorting additional money

Sophos X-Ops also uncovered a new scammer tactic designed to extort additional money. Traditionally, when victims of CryptoRom scams attempt to cash in on their “profits,” fraudsters will tell them they need to pay a 20% tax on their funds before completing any withdrawals.

However, a recent victim revealed that after paying the “tax” to withdraw money, the fraudsters said the funds had been “hacked” and they would need another 20% deposit before receiving the funds.

Fake cryptocurrency investment apps

Upon further investigation, researchers found seven fake cryptocurrency investment apps in the official Google Play and Apple App stores. These apps have seemingly benign descriptions in the app stores. However, users face a fake crypto-trading interface when they open the app.

To get past the Apple App Store review process, the app developers use the same technique Sophos first reported on in February 2023. They submit the app for approval using legitimate, run-of-the-mill web content. Then, once the app has been approved and published, they modify the server hosting the app with code for the fraudulent interface.

Advertisement

Many of these seven new apps recycled the same templates and descriptions, suggesting the same one or two pig butchering rings are creating the scheme.

“Prior to being able to get their apps into the Apple Store, CryptoRom fraudsters had to use an awkward technical workaround to target iOS users, which could alert their victims that something was amiss. Now, it’s much easier for them to target iPhone users, expanding their victim pool. These apps are also easy to recycle and reuse. While we’ve alerted Google and Apple to these latest apps, it’s likely more will pop up,” concluded Gallagher.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Crypto

Streamlined Cryptocurrency-Focused Apps

Published

on

Streamlined Cryptocurrency-Focused Apps
Blaqclouds, Inc. has introduced ShopwithCrypto.io, a Progressive Web App designed to enhance cryptocurrency usability in daily transactions. This app offers a streamlined, multi-device experience that supports over 250 cryptocurrencies across major blockchain networks like ETH, BNB, and MATIC.

Key features of ShopwithCrypto.io include offline functionality, QR code integration, and the ability to purchase gift cards from global merchants, all while ensuring security and transparency through the ZEUS Blockchain. The Progressive Web App’s lightweight design and compatibility with both Android and iOS platforms make it accessible without the need for app store downloads. By combining ease of use with robust security measures, it aims to bridge the gap between digital assets and real-world spending. Its integration with popular wallets like MetaMask allows users to manage their transactions seamlessly while maintaining control of private keys.

Image Credit: Blaqclouds, Inc.

Continue Reading

Crypto

Delta police targeting cryptocurrency scams

Published

on

Delta police targeting cryptocurrency scams

DPD and blockchain analytics company Chainalysis co-hosted other law enforcement agencies and cryptocurrency exchanges for ‘Operation DeCloak’

A cryptocurrency fraud workshop co-hosted by the Delta Police Department last fall identified over 1,100 victims worldwide, including a ‘significant number’ in Canada.

On Sept. 16 and 17, 2024, the DPD and blockchain analytics company Chainalysis hosted “Operation DeCloak,” bringing together representatives from law enforcement agencies including the RCMP, Victoria Police Department, Vancouver Police Department, the BC Securities Commission, the BC Prosecution Service and the BC Financial Services Authority, as well as key stakeholders from cryptocurrency exchanges such as Shakepay and others.

The initiative was a localized “sprint” of Chainalysis’ “Operation Spincaster,” a series of public-private collaborations designed to disrupt and prevent cryptocurrency scams. Spincaster itself spun out from “Operation Disruption,” a collaboration between Chainalysis and the Calgary Police Service in March 2024.

“Leveraging the transparency of the blockchain, Chainalysis proactively identified thousands of compromised wallets. This actionable intelligence formed the basis of a series of operational sprints across six countries (U.S., U.K., Canada, Spain, Netherlands and Australia) with over 100 attendees, including 12 public sector agencies and 17 crypto exchanges,” the company said in a press release.

Advertisement

“Over 7,000 leads were disseminated during these sprints, relating to approximately US$162 million of losses. These leads were used to close accounts, seize funds and build intelligence to prevent future scams.”

During last fall’s Operation DeCloak, Chainalysis led training sessions in investigating leads, tracing stolen funds and identifying compromised wallets using the company’s proprietary “Crypto Investigations Solution.”

According to a DPD press release, 240 crypto addresses were closely examined, revealing an estimated collective loss of C$35 million.

SEE ALSO: Court rejects environmental challenge to massive Delta port expansion

The event also promoted proactive policing and disruption strategies aimed at combating fraud, with particular emphasis on a growing tactic known as “approval phishing” used by romance and investment scammers targeting cryptocurrency transactions. 

Advertisement

The method involves scammers gaining their victim’s trust by promoting false investment opportunities with the promise of high returns, thereby convincing victims to unknowingly approve malicious blockchain transactions.

The initial transaction gives the scammer access to tokens in the victim’s digital wallet without the victim’s knowledge, resulting in unauthorized withdrawals.

Police say scammers typically connect with their victims through social media, or via apps or pop-up ads.

During Operation DeCloak, police say immediate steps were taken to notify identified victims of these scams.

“With the co-operation of the exchange companies, affected individuals were promptly contacted with the goal of preventing further harm,” the DPD said in its press release.

Advertisement

Since the workshop, the department has successfully deployed the techniques learned through Operation DeCloak. 

“The technique was applied to a previous investigation which identified stolen cryptocurrency funds in a blacklisted address containing US$1.2 million. This address was in the process of being seized by an overseas police agency,” the department said.

Using the DeCloak techniques, the DPD’s Cybercrime Unit has identified an additional 70 transactions worth US$800,000 sent from Canadian exchanges. Investigators are identifying those victims and seizing the funds from the blacklisted address so they can be returned.

“This collaboration with Chainalysis and cryptocurrency exchanges is a testament to the DPD’s focus on innovation and commitment to community safety and well-being.”

SEE ALSO: Conservative candidate files court petition over Surrey ‘voting irregularities’

Advertisement

SEE ALSO: Good Samaritan saves 3 people in fiery single-car crash in Surrey

Continue Reading

Crypto

Coinbase Investigates ‘Delayed Sends’ for XRP on Its Platform | PYMNTS.com

Published

on

Coinbase Investigates ‘Delayed Sends’ for XRP on Its Platform | PYMNTS.com

Cryptocurrency exchange Coinbase said Tuesday (Jan. 14) that it is investigating a problem with delayed sends of Ripple (XRP) on its platform.

“We are aware that some users may be experiencing delayed sends for Ripple (XRP),” Coinbase said in an incident report on its status page. “Buys, Sells and Fiat withdrawals/deposits are not affected. We are investigating this issue and will provide an update shortly.”

In an earlier, separate report on its status page, Coinbase said some users experienced delayed sends and receives for Stellar (XLM) on Friday (Jan. 10). That incident was resolved within 90 minutes.

On Thursday (Jan. 9), some users experienced latency or degraded performance with buys, sells, sends, Coinbase Onramp and Advanced Trade. That issue was resolved within two hours, according to the page.

In other, separate news about the company, it was reported Thursday (Jan. 9) that Coinbase told customers that it may have to share data demanded by the Commodity Futures Trading Commission (CFTC).

Advertisement

The regulator sent a subpoena to the firm that seeks information about Coinbase customers’ interactions with prediction market firm Polymarket, and Coinbase emailed some customers saying it may have to share that data with the CFTC.

“When we receive requests for information from a government, each request is carefully reviewed by a team of trained experts using established procedures to determine its legal sufficiency,” a Coinbase spokesperson told CoinDesk.

On Dec. 9, cryptocurrency payments solution firm Triple-A announced an integration with Coinbase that it said it designed to let Coinbase users make payments to select merchants in the Triple-A network.

“Triple-A’s integration with Coinbase Commerce will empower merchants to offer a Coinbase-specific payment option, enhancing the convenience for Coinbase users and allowing Coinbase to connect with a wider network of merchants, to drive the broader adoption of cryptocurrency payments,” the company said in a press release.

Coinbase upgraded its Coinbase One subscription program and launched a new tier called Coinbase One Premium on Dec. 4, saying that with these new offerings, “Coinbase One now truly benefits all types of traders.”

Advertisement

Coinbase One membership has reached 600,000 across 42 countries, the company added.

Continue Reading

Trending