Beware cool-looking beta crypto-apps. They may be money-stealing fakes
- Reference: 1692051732
- News link: https://www.theregister.co.uk/2023/08/14/fbi_mobile_beta_testing_apps/
- Source link:
That malicious code may steal data from devices, access and drain online financial accounts, or completely hijack the handhelds.
By dressing up these apps as beta tests, crooks can persuade curious netizens to download and install them from outside the normal app stores, bypassing whatever passes as a review process these days. The fraudsters make sure the applications look as legit as possible, we're told, using names, images, and designs found in official apps.
[1]
The Feds says they're aware of "unidentified cyber criminals" luring marks with phishing emails or [2]romance scams ; the end result being the scammers build up a level of trust – even fake relationships – with their victims to the point where those folks are tricked into downloading and installing malicious apps.
[3]
[4]
That process may well involve walking the victim through effectively jail-breaking their device, or making changes to their settings to install apps outside of the operating system's official software store, judging from the FBI's description of the scam. The Feds talk of people being lured into downloading "a mobile beta-testing app housed within a mobile beta-testing app environment."
Unsurprisingly, these bogus apps tend to be those of cryptocurrency exchanges, with promises of fat returns on investment. The victims are fooled into entering their online financial account information into the application, believing those details will be used to transfer and invest their money, but instead the funds are sent to criminal-controlled wallets.
[5]
It's essentially a fresh twist on so-called pig-butchering scams, which the FBI has been warning about for a couple of years and are costing victims [6]hundreds of millions of dollars.
In [7]today's alert , the FBI also suggested some red flags that may indicate you've unknowingly downloaded a malicious app.
These include the battery draining faster than usual, or the device taking a really long time to process requests. Folks should also be on alert for unauthorized apps appearing on their phones, apps that request access to permissions that have nothing to do with their functionality, and persistent pop-up ads.
[8]
It says something about the mobile software ecosystem when the above red flags could apply to real legit applications.
[9]Feds seize $112m in cryptocurrency linked to 'pig-butchering' finance scams
[10]Romance scammers' favorite lies cost victims $1.3B last year
[11]INTERPOL shutters '16shop' phishing-as-a-service outfit
[12]'Pig butchering' romance scam domains seized and slaughtered by the Feds
Additionally, apps that boast a ton of downloads but have no or very few reviews, and those with spelling or grammatical errors or a lack of details in the description are highly suspect, the agents said. Download at your own risk — or, better yet, just don't download them at all.
And, as always, check the developers' info and customer reviews before downloading any app to your mobile device, and do not provide personal or financial information to someone you've only met online. If someone promises you something from basically nothing, it probably is too good to be true.
Banks, healthcare offices, and other legit organizations also aren't going to ask you to provide personal, financial, or health-related information in an email – if they do, tell them that's unacceptable – and warnings out of the blue along the lines of "do X or your account will be closed" are likely fake. Double check with the source.
Other advice to live by: don't trust links in emails or text messages, and scan attachments before opening them. Keep your software up to date, and restrict app permissions, and uninstall ones that you don't use. Feel free to share more tips in the comments section. This isn't an exhaustive list, though it does feel a little "to be safe on the internet, don't do anything. At all."
Which we know isn't entirely helpful.
Here's hoping this heads-up will help you avoid becoming one of the hundreds of thousands of victims who lost more than $10.2 billion
[13]PDF
to cybercriminals last year alone, though. ®Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZNr4cFIkuHbgIaGndRMXqwAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2023/02/10/romance_scammers_cost_victims_13b/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNr4cFIkuHbgIaGndRMXqwAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNr4cFIkuHbgIaGndRMXqwAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZNr4cFIkuHbgIaGndRMXqwAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/04/04/fbi_pig_butchering_cryptocurrency/
[7] https://www.ic3.gov/Media/Y2023/PSA230814
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZNr4cFIkuHbgIaGndRMXqwAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2023/04/04/fbi_pig_butchering_cryptocurrency/
[10] https://www.theregister.com/2023/02/10/romance_scammers_cost_victims_13b/
[11] https://www.theregister.com/2023/08/09/interpol_16shop_phishing_shutdown/
[12] https://www.theregister.com/2022/11/23/pig_butchering_domains_seized/
[13] https://www.ic3.gov/Media/PDF/AnnualReport/2022_IC3Report.pdf
[14] https://whitepapers.theregister.com/
"most virus scanners miss a frighteningly large fraction of malicious attachments."
That's because the attachment isn't malware or a virus. It's just a link that takes you someplace where you get asked to fill out forms and enter banking information just like any shopping portal. It might be trying to get you to dl a piece of software. It's as bad as all of the QR codes that people will just scan without a thought. I've had people want me to get a virtual business card from them by scanning a QR code on their phone and I just have to shake my head and walk away.
"Beware cool-looking beta crypto-apps. They may be money-stealing fakes"
...as opposed to inevitably-money-losing genuine ones?
'money-stealing fakes'
So these are even faster scams than the real crypto apps, which are pyramid scheme scams but generally longer term?
If you don't expect the attachment, don't know exactly what's in it, and don't know how to find out without 'opening' it, then it's probably best just to delete it.
In my experience most virus scanners miss a frighteningly large fraction of malicious attachments. Few will reliably find even four out of five. Some find no more than a few percent.
Don't open any unknown attachment, even if you have scanned it.
Sometimes it's a risk even to use the scanner on your computer to scan an attachment.
If you really know what you're doing you might want to send it for scanning at Virustotal or Jotti.
But whatever you do, don't bet on the result.