• bitcoinBitcoin (BTC) $ 80,067.00
  • ethereumEthereum (ETH) $ 2,373.62
  • tetherTether (USDT) $ 0.999749
  • xrpXRP (XRP) $ 1.41
  • bnbBNB (BNB) $ 624.65
  • usd-coinUSDC (USDC) $ 0.999842
  • solanaSolana (SOL) $ 85.25
  • tronTRON (TRX) $ 0.338281
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.113075
  • whitebitWhiteBIT Coin (WBT) $ 59.93
  • usdsUSDS (USDS) $ 0.999819
  • hyperliquidHyperliquid (HYPE) $ 41.97
  • cardanoCardano (ADA) $ 0.253497
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 10.34
  • bitcoin-cashBitcoin Cash (BCH) $ 448.77
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 397.50
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • zcashZcash (ZEC) $ 421.51
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • chainlinkChainlink (LINK) $ 9.33
  • canton-networkCanton (CC) $ 0.148476
  • stellarStellar (XLM) $ 0.160716
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • daiDai (DAI) $ 0.999538
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 56.09
  • avalanche-2Avalanche (AVAX) $ 9.29
  • ethena-usdeEthena USDe (USDE) $ 0.999220
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 3.01
  • hedera-hashgraphHedera (HBAR) $ 0.089054
  • suiSui (SUI) $ 0.939227
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007562
  • the-open-networkToncoin (TON) $ 1.38
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.069026
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • bittensorBittensor (TAO) $ 290.61
  • tether-goldTether Gold (XAUT) $ 4,600.05
  • global-dollarGlobal Dollar (USDG) $ 0.999864
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • pax-goldPAX Gold (PAXG) $ 4,600.01
  • mantleMantle (MNT) $ 0.640247
  • uniswapUniswap (UNI) $ 3.33
  • polkadotPolkadot (DOT) $ 1.24
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.059125
  • skySky (SKY) $ 0.081205
  • pi-networkPi Network (PI) $ 0.176959
  • okbOKB (OKB) $ 86.09
  • falcon-financeFalcon USD (USDF) $ 0.996545
  • aster-2Aster (ASTER) $ 0.679388
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • pepePepe (PEPE) $ 0.000004
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.30
  • ripple-usdRipple USD (RLUSD) $ 0.999857
  • usddUSDD (USDD) $ 0.999829
  • ondo-financeOndo (ONDO) $ 0.301664
  • bitget-tokenBitget Token (BGB) $ 2.06
  • aaveAave (AAVE) $ 94.27
  • ethereum-classicEthereum Classic (ETC) $ 8.69
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • internet-computerInternet Computer (ICP) $ 2.40
  • bfusdBFUSD (BFUSD) $ 0.999187
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • morphoMorpho (MORPHO) $ 1.99
  • kucoin-sharesKuCoin (KCS) $ 8.53
  • united-stablesUnited Stables (U) $ 1.00
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.096496
  • algorandAlgorand (ALGO) $ 0.114975
  • quant-networkQuant (QNT) $ 69.53
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.07
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.92
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.75
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.85
  • kaspaKaspa (KAS) $ 0.034291
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • ethenaEthena (ENA) $ 0.106633
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.907837
  • gatechain-tokenGate (GT) $ 7.38
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 1.01
  • worldcoin-wldWorldcoin (WLD) $ 0.241943
  • wbnbWrapped BNB (WBNB) $ 759.61
  • filecoinFilecoin (FIL) $ 0.969033
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • stable-2​​Stable (STABLE) $ 0.032854
  • arbitrumArbitrum (ARB) $ 0.119070
  • justJUST (JST) $ 0.084817
  • pump-funPump.fun (PUMP) $ 0.001859
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010476
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007589
  • vechainVeChain (VET) $ 0.007344
  • beldexBeldex (BDX) $ 0.080050
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • ousgOUSG (OUSG) $ 115.10
  • jupiter-exchange-solanaJupiter (JUP) $ 0.181620
  • hash-2Provenance Blockchain (HASH) $ 0.011221
  • ghoGHO (GHO) $ 0.999848
  • xdce-crowd-saleXDC Network (XDC) $ 0.029257
  • usdtbUSDtb (USDTB) $ 0.999215
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • dashDash (DASH) $ 45.13
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • bonkBonk (BONK) $ 0.000006
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • usual-usdUsual USD (USD0) $ 0.998882
  • official-trumpOfficial Trump (TRUMP) $ 2.36
  • skyaiSkyAI (SKYAI) $ 0.539495
  • clbtcclBTC (CLBTC) $ 76,920.00
  • siren-2Siren (SIREN) $ 0.759342
  • yldsYLDS (YLDS) $ 0.999960
  • midnight-3Midnight (NIGHT) $ 0.031378
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.774430
  • megausdMegaUSD (USDM) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.51
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • true-usdTrueUSD (TUSD) $ 0.998626
  • a7a5A7A5 (A7A5) $ 0.012476
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000089
  • tbtctBTC (TBTC) $ 70,942.00
  • dexeDeXe (DEXE) $ 10.22
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.210565
  • venice-tokenVenice Token (VVV) $ 9.72
  • edgexedgeX (EDGE) $ 1.27
  • euro-coinEURC (EURC) $ 1.17
  • aerodrome-financeAerodrome Finance (AERO) $ 0.457879
  • chilizChiliz (CHZ) $ 0.041026
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • blockstackStacks (STX) $ 0.227868
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • adi-tokenADI (ADI) $ 4.03
  • sei-networkSei (SEI) $ 0.060143
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.402572
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998831
  • tezosTezos (XTZ) $ 0.369918
  • build-onBUILDon (B) $ 0.393755
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • usxUSX (USX) $ 0.999671
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • injective-protocolInjective (INJ) $ 3.77
  • humanityHumanity (H) $ 0.204884
  • sun-tokenSun Token (SUN) $ 0.019135
  • monadMonad (MON) $ 0.030676
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • curve-dao-tokenCurve DAO (CRV) $ 0.239940
  • spx6900SPX6900 (SPX) $ 0.388367
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • manadiaManadia (UMXM) $ 1.72
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • ether-fiEther.fi (ETHFI) $ 0.423146
  • kinesis-goldKinesis Gold (KAU) $ 147.78
  • layerzeroLayerZero (ZRO) $ 1.39
  • decredDecred (DCR) $ 19.80
  • gnosisGnosis (GNO) $ 129.41
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • zebec-networkZebec Network (ZBCN) $ 0.003483
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • celestiaCelestia (TIA) $ 0.357483
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • unibaseUnibase (UB) $ 0.129373
  • hastra-primePRIME (PRIME) $ 1.04
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • conflux-tokenConflux (CFX) $ 0.061919
  • bitcoin-svBitcoin SV (BSV) $ 16.02
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • lido-daoLido DAO (LDO) $ 0.374206
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • flokiFLOKI (FLOKI) $ 0.000033
  • apenftAINFT (NFT) $ 0.00000032
  • usdgoUSDGO (USDGO) $ 1.00
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • olympusOlympus (OHM) $ 19.26
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

New trojan wave targets crypto wallets and banking apps

0 1

New trojan wave targets crypto wallets and banking apps

Cybersecurity researchers have found four active families of Android malware that are targeting +800 apps, including cryptocurrency wallets and banking apps. These malware use methods that most traditional security tools can’t detect.

Zimperium’s zLabs team released results tracking the trojans known as RecruitRat, SaferRat, Astrinox, and Massiv.

According to the company’s research, each family has its own command-and-control network that they use to steal login information, take over financial transactions, and get user data from infected devices.

Crypto and banking apps face new threats from multiple malwares

The malware families are a direct threat to anyone who manages crypto on Android.

Once installed, the trojans can put fake login screens on top of real crypto and banking apps, stealing passwords and other private information in real time. The malware then puts a fake HTML page over the real app interface, making what the company called “a highly convincing, deceptive facade.”

“Using Accessibility Services to monitor the foreground, the malware detects the exact moment a victim launches a financial application,” wrote security researchers from Zimperium.

According to the report, the trojans can do more than just steal credentials. They can also capture one-time passcodes, stream a device’s screen to attackers, hide their own app icons, and stop people from uninstalling them.

Each campaign uses a different bait to get people to fall for it.

SaferRat spread itself by using fake websites that promised free access to premium streaming services. RecruitRat hid its payload as part of a job application process, sending targets to phishing sites that asked them to download a malicious APK file.

Astrinox used the same kind of recruitment-based method, using the domain xhire[.]cc. Depending on the device used to visit that site, it showed different content.

Android users were asked to download an APK, and iOS users saw a page that looked like the Apple App Store. However, security researchers found no proof that iOS was actually hacked.

It was not possible to confirm how Massiv was distributed during the research cycle.

All four trojans used phishing infrastructure, text-message scams, and social engineering that played on people’s need to act quickly or their curiosity to get them to sideload apps that were harmful.

Crypto malware evades detection

The campaigns aim to get around security tools.

Researchers found that the malware families use advanced anti-analysis techniques and structural tampering with Android application packages (APKs) to keep what the company called “near-zero detection rates against traditional signature-based security mechanisms.”

Network communications also mix in with regular traffic. The trojans use HTTPS and WebSocket connections to talk to their command servers. Some versions add extra layers of encryption on top of these connections.

Another important thing is persistence. Modern Android banking trojans no longer use simple, one-stage infections. Instead, they use multi-stage installation processes that are meant to get around Android’s changing permission model, which has made it harder for apps to do things without the user’s explicit permission.

The report did not identify particular crypto wallets or exchanges within the +800 targeted applications. But because of overlay attacks, passcode interception, and screen streaming, any Android-based crypto app could be at risk if a user installs a malicious APK from outside the Google Play Store.

Downloading apps from links in text messages, job postings, or promotional websites is still one of the guaranteed ways for mobile malware to get into a smartphone.

People who manage their crypto on Android devices should only use official app stores and be wary of pop-up messages that ask them to download something.

Source

Leave A Reply

Your email address will not be published.