Fake bitcoin wallet address

fake bitcoin wallet address

Bitcoin Wallet Script Start your very own web-based bitcoin wallet service and earn a income from the Your wallet address never appears on the public blockchain and nobody knows how many coins you have. SHERUBIT FAKE BITCOIN. ESET researchers have analyzed fake cryptocurrency wallets is that the app pretends to generate a unique wallet address where users can. It is also possible to get a Bitcoin invoice address using an account at an exchange or online wallet service. There are currently three invoice.

Fake cryptocurrency apps crop up on Google Play as bitcoin price rises

ESET researchers have analyzed fake cryptocurrency wallets emerging on Google Play at the time of bitcoin’s renewed growth

May has seen bitcoin growing, with its price climbing to its highest points since September Not surprisingly, cybercrooks were quick to notice this development and started upping their efforts in targeting cryptocurrency users with various scams and malicious apps.

One such app was recently spotted on Google Play by Reddit users, impersonating the popular hardware cryptocurrency wallet Trezor and using the name “Trezor Mobile Wallet”. We haven’t previously seen malware misusing Trezor’s branding and were curious about the capabilities of such a fake app. After all, Trezor offers hardware wallets that require physical manipulation and authentication via PIN, or knowledge of the so called recovery seed, to access the stored cryptocurrency. Similar constraints apply to its official app, “TREZOR Manager”.

Analyzing the fake app, we found that:

  1. it can’t to do any harm to Trezor users given Trezor’s multiple security layers;
  2. it is connected to a fake cryptocurrency wallet app named “Coin Wallet &#; Bitcoin, Ripple, Ethereum, Tether”, which is capable of scamming unsuspecting users out of money; and
  3. both these apps were created based on an app template sold online.

We have reported the fake Trezor app to Google’s security teams and reached out to Trezor about the publication of this blogpost. Trezor confirmed the fake app did not pose a direct threat to their users. However, they did express concern that the email addresses collected via fake apps such as this one could be later misused for phishing campaigns targeted against Trezor users.

At the time of writing, neither the fake Trezor app nor the Coin Wallet app are available on Google Play.

The app masquerading as a mobile wallet for Trezor was uploaded to Google Play on May 1, under the developer name “Trezor Inc.”, as seen in Figure 1. Overall, the app’s page on Google Play appeared trustworthy – the app name, developer name, app category, app description and images all seem legitimate at first glance. At the time of our analysis, the fake app even came up as the second result when searching for “Trezor” on Google Play, right after Trezor’s official app.

Figure 1. The fake app on Google Play

What does it do?

The convincing disguise, however, begins and ends on Google Play. After installation, the icon that appears on users’ screens differs from the one seen on Google Play, which serves as a clear indicator of something fishy. The icon of the installed app has “Coin Wallet” in it, as seen in Figure 2.

Figure 2. The icon of “Trezor Mobile Wallet” after installation

Furthermore, when users launch the app, a generic login screen is displayed, with no mention of Trezor, as seen in Figure 3. This is another indicator we are not dealing with a legitimate app. This generic screen is used to phish for login credentials – but it is unclear exactly what credentials, and what possible use they could be to attackers. Either way, whatever users enter into the fake login form is sent to the attacker’s server, as shown in Figure 4.

Figure 3. The generic login screen displayed by the fake app

Figure 4. The entered credentials are sent to the attacker’s server

As seen in Figure 4, the server used to harvest credentials from the fake Trezor app is hosted on coinwalletinc[.]com. Looking into the domain led us to another fraudulent app, named “Coin Wallet” on its website and “Coin Wallet &#; Bitcoin, Ripple, Ethereum, Tether” on Google Play. This app is described in the following section of this blogpost.

The Coin Wallet app and the fake Trezor app described in the previous section have a lot in common – besides using the same server, they also overlap in code and interface. The Coin Wallet app uses the same icon that we have seen in the fake Trezor app after installation.

On its website, the Coin Wallet app is described as the “World’s leading Coin Wallet”, as seen in Figure 5.

Figure 5. The Coin Wallet app’s deceptive presentation on its website

The website contains a link to Google Play, where the app was available from February 7, until May 5, under the name “Coin Wallet &#; Bitcoin, Ripple, Ethereum, Tether”, as seen in Figure 6. During that time, it was installed by more than users.

The website also appears to link to Apple’s App Store, but clicking the “Available on the App Store” button only leads to the URL of the PNG image.

Figure 6. The fraudulent Coin Wallet app on Google Play

What does it do?

The app claims it lets its users create wallets for various cryptocurrencies. However, its actual purpose is to trick users into transferring cryptocurrency into the attackers’ wallets – a classic case of what we named wallet address scams in our previous research of cryptocurrency-targeting malware.

How this works is that the app pretends to generate a unique wallet address where users can transfer their coins. In reality, this address belongs to the attackers’ wallet, as only they have the private key necessary for accessing the funds. The attackers have one wallet for each supported cryptocurrency – 13 wallets altogether – and all victims with any specific targeted cryptocurrency are given the same wallet address.

Looking at the shared graphic elements of this and the fraudulent Trezor app, it seems that both have been created on the same basis. A Google search for “coinwallet app template” returns a generic “Android cryptocurrency wallet template” available for $ The template itself is a benign asset turned malicious in the hands of attackers; however, we see here how such assets may be used by more attackers to create deceptive apps quickly and cheaply.

If bitcoin continues its growth trend, we can expect more cryptocurrency scam apps to emerge in the official Android app store and elsewhere. When installing apps, it is important to stick to some basic security principles – even more so when money is at stake.

  • Only trust cryptocurrency-related and other finance apps if they are linked from the official website of the service
  • Only enter your sensitive information into online forms if you are certain of their security and legitimacy
  • Keep your device updated
  • Use a reputable mobile security solution to block and remove threats
Package NameHashDetection
tallerembajador.com.mxcurrencyAC8CEBA40FBCCA6DD76Dtallerembajador.com.mxd/tallerembajador.com.mx
tallerembajador.com.mxcurrencyEE9E4ADA0F0CFB0FB0B85Ctallerembajador.com.mxd/tallerembajador.com.mx
CryptocurrencyWallet
BTC17jAe7hTZgNixT4MPZVGZD7fGKQpD9mppi
DOGEDGf6dT2rd9evb4d6X9mzjd9uaFoyywjfrm
ETH0xd83F74adf1E6ACc3cCCbEA4b01E92C
LTCLg64xV4Mw41bV3pTKc5ooBJ4QZ81gHUuJ6
BCHqq9cjckr3r9wl5x4f3xcfshpcj72jcqk9uu2qa7ja2
DASHXu6mkZNFxSGYFcDUEVWtUEcoMnfoGryAjS
ZECt1JKPTwHJcj6e5BDqLp5KayaXLWdMs6pKZo
XRPraPXPSnw61Cbn2NWky39CrCL1AZC2dg6Am
USDT0xd83F74adf1E6ACc3cCCbEA4b01E92C
XLMGDZ2AT7TU6N3LTMHUIX6J2DZHUDBU74X65ASOWEZUQGP7JMQKDBUX
TRXTAm4fPA6yTQvaAjKs2zFqztfDPmnNzJqi2
ADADdzFFzCqrhswWLJMdNPJK8EL2d5JdN8cSU1hbgStPhxDqLspXGRRgWkyknbw45KDvT2EJJhoPXuj2Vdsj6V6WWM5JABoZ4UhR7vnRopn
NEOAJqeUDNrn1EfrPxUriKuRrYyhobhk78zvK
Источник: tallerembajador.com.mx

2 thoughts to “Fake bitcoin wallet address”

Leave a Reply

Your email address will not be published. Required fields are marked *