Tuesday, January 19, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Privacy

First Android Clipboard Hijacking Crypto Malware Found On Google Play Store

February 11, 2019
in Internet Privacy
First Android Clipboard Hijacking Crypto Malware Found On Google Play Store
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Credit: The Hacker News

A security researcher has discovered yet another cryptocurrency-stealing malware on the official Google Play Store that was designed to secretly steal bitcoin and cryptocurrency from unwitting users.

You might also like

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security

WhatsApp Delays Controversial ‘Data-Sharing’ Privacy Policy Update By 3 Months

NSA Suggests Enterprises Use ‘Designated’ DNS-over-HTTPS’ Resolvers

The malware, described as a “Clipper,” masqueraded as a legitimate cryptocurrency app and worked by replacing cryptocurrency wallet addresses copied into the Android clipboard with one belonging to attackers, ESET researcher Lukas Stefanko explained in a blog post.

Since cryptocurrency wallet addresses are made up of long strings of characters for security reasons, users usually prefer copying and pasting the wallet addresses using the clipboard over typing them out.

The newly discovered clipper malware, dubbed Android/Clipper.C by ESET, took advantage of this behavior to steal users cryptocurrency.

To do this, attackers first tricked users into installing the malicious app that impersonated a legitimate cryptocurrency service called MetaMask, claiming to let users run Ethereum decentralized apps in their web browsers without having to run a full Ethereum node.

Officially, the legitimate version of MetaMask is only available as a web browser extension for Chrome, Firefox, Opera, or Brave, and is not yet launched on any mobile app stores.

However, Stefanko spotted the malicious MetaMask app on Play Store targeting users who want to use the mobile version of the service by changing their legitimate cryptocurrency wallet address to the hacker’s own address via the clipboard.

As a result, users who intended to transfer funds into a cryptocurrency wallet of their choice would instead make a deposit into the attacker’s wallet address pasted by the malicious app.

“Several malicious apps have been caught previously on Google Play impersonating MetaMask. However, they merely phished for sensitive information with the goal of accessing the victims’ cryptocurrency funds,” Stefanko said.

“Android Clipper targeted Bitcoin and Ethereum cryptocurrency addresses when being copied in to clipboard and replaced them with the attacker’s wallet address. Once this transaction is sent, it can not be canceled.”

Stefanko spotted the malicious MetaMask app, which he believes was the first Android Trojan Clipper to be discovered on Play Store, shortly after its introduction to the app store on February 1.

Google took down the malicious app almost immediately after being notified by the researcher.

While the bitcoin price has been dropped steadily since hitting its all-time high in December 2017, there is no reduction (in fact rise) in the cryptocurrency scandals, thefts, and scams that continue to plague the industry.

Just last week, The Hacker News reported how customers of the largest Canadian bitcoin exchange QuadrigaCX lost $145 million in cryptocurrency after the sudden death of its owner who was the only one with access to the company’s cold (offline) storage wallets. However, some users and researchers are suggesting the incident could be an exit scam.


Credit: The Hacker News By: noreply@blogger.com (Swati Khandelwal)

Previous Post

Machine learning tool helps prioritize vulnerabilities

Next Post

Microsoft: 70 percent of all security bugs are memory safety issues

Related Posts

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security
Internet Privacy

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security

January 18, 2021
WhatsApp Delays Controversial ‘Data-Sharing’ Privacy Policy Update By 3 Months
Internet Privacy

WhatsApp Delays Controversial ‘Data-Sharing’ Privacy Policy Update By 3 Months

January 16, 2021
NSA Suggests Enterprises Use ‘Designated’ DNS-over-HTTPS’ Resolvers
Internet Privacy

NSA Suggests Enterprises Use ‘Designated’ DNS-over-HTTPS’ Resolvers

January 16, 2021
Joker’s Stash, The Largest Carding Marketplace, Announces Shutdown
Internet Privacy

Joker’s Stash, The Largest Carding Marketplace, Announces Shutdown

January 16, 2021
Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
Internet Privacy

Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks

January 15, 2021
Next Post
Microsoft: 70 percent of all security bugs are memory safety issues

Microsoft: 70 percent of all security bugs are memory safety issues

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Oracle takes a new twist on MySQL: Adding data warehousing to the cloud service
Internet Security

Google Cloud: We do use some SolarWinds, but we weren’t affected by mega hack

January 19, 2021
Google is Rethinking its Business – What About You?
Data Science

Google is Rethinking its Business – What About You?

January 18, 2021
Covalent and IBM partnership looks to fashion sustainability through blockchain
Blockchain

Covalent and IBM partnership looks to fashion sustainability through blockchain

January 18, 2021
Get the machine learning for beginners overview bundle for under $20
Machine Learning

Get the machine learning for beginners overview bundle for under $20

January 18, 2021
Singapore tightens cyber defence guidelines for financial services sector
Internet Security

Singapore tightens cyber defence guidelines for financial services sector

January 18, 2021
FairML: Auditing Black-Box Predictive Models
Data Science

FairML: Auditing Black-Box Predictive Models

January 18, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Google Cloud: We do use some SolarWinds, but we weren’t affected by mega hack January 19, 2021
  • Google is Rethinking its Business – What About You? January 18, 2021
  • Covalent and IBM partnership looks to fashion sustainability through blockchain January 18, 2021
  • Get the machine learning for beginners overview bundle for under $20 January 18, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates