Fake Crypto Wallet App Imitating Trezor Found on Google Play Store

Published at: May 23, 2019

Fraudsters have been adding fake cryptocurrency wallets to the Google Play store in an attempt to cash in on rising bitcoin (BTC) prices, ESET antivirus researchers claimed on May 23.

One malicious app imitated the hardware wallet Trezor — and the investigation found that the software had ties to another fake app that has the potential to scam unsuspecting users out of money.

While the app’s page on Google Play looked legitimate, the researchers said the software itself contains no Trezor branding at all, with a generic login screen phishing for credentials.

According to ESET, more than 1,000 users had downloaded one of the dodgy apps. Although it claimed to enable its customers to create wallets for storing their crypto, the software was actually designed to trick them into transferring coins to addresses owned by the attackers. The researchers warned:

“If bitcoin continues its growth trend, we can expect more cryptocurrency scam apps to emerge in the official Android app store and elsewhere.”

Crypto users are being urged to only trust an app if the company’s official website links to it, regularly update their devices and think twice before entering their sensitive information into online forms.

Trezor told the researchers that the fake app did not appear to pose a security threat to its users, but the company said it was concerned that the email addresses collected through the software could be used for phishing attempts in the future. Google Play has since removed the apps from its marketplace.

Last year, Trezor issued a warning to users after fraudsters began to make counterfeit versions of its hardware wallets.

Back in November 2018, malware researcher Lukas Stefanko found four fake crypto wallets on the Google Play Store that were posing as official pieces of software for neo, tether and metamask.

Tags
Neo
Related Posts
Four Fake Cryptocurrency Wallets Found on Google Play Store
Malware researcher Lukas Stefanko has found four fake cryptocurrency wallets on the Google Play Store that were trying to steal users’ personal data, according to a blog post published Nov. 13. The apps were posing as cryptocurrency wallets for NEO, Tether and an extension for accessing Ethereum (ETH), MetaMask. They were purportedly designed to phish users’ mobile banking credentials and credit card information. Stefanko classified the wallets into two groups, wherein the fake MetaMask app was a “phishing wallet” and the other three apps were “fake wallets.” Once the phishing app is installed and launched, it requests the user's private …
Ethereum / Nov. 15, 2018
Fake MetaMask Crypto Malware Pulled From Google Play After Tipoff
Decentralized app (DApp) MetaMask is facing fresh problems from cryptocurrency scammers after malware impersonating the tool appeared on Google Play, cybersecurity company Eset reported on Feb. 8. The malware, which replaces computer clipboard information in an attempt to steal cryptocurrency, was removed by Google at the beginning of the month after a tipoff from Eset researchers. Known as a “Clipper,” the malware replaces copied cryptocurrency wallet addresses with an address belonging to an attacker in the hope that funds will be sent elsewhere without the user noticing. The discovery marked the first time such malware had made it past Google’s …
Ethereum / Feb. 11, 2019
Bitcoin stealing malware: Bitter reminder for crypto users to stay vigilant
An unfortunate Bitcoin (BTC) user was duped out of 0.255 BTC, almost $10,000, due to malware running on their computer. Louis Nel, a tech blogger and crypto enthusiast, flagged the issue on Twitter, referring to his friend as ‘C.’ A friend sent 0.255BTC from his bitcoin wallet to an exchange. He copied and pasted the wallet address on his computer. After 4 hours he was worried when the funds did not arrive at the exchange... — Louis Nel (@LouisNel) March 14, 2022 Nel told Cointelegraph that C’s “Bitcoin was sent from Kraken to VALR, a South African exchange,” however, “malware …
Blockchain / March 15, 2022
You can now search ETH addresses on Google — But what about Bitcoin?
Google’s latest crypto feature enables some Ethereum wallet addresses to have their ETH balances tracked straight off of the Google search engine — saving the need to make the trip to Etherscan. The feature was first made public by the Principal of Google Ventures Han Hua in an Oct. 11 Twitter post. Well done, blockchain address is now available in Google Search! pic.twitter.com/7IuKv1gddR — Han⚡️ (@hhua_) October 11, 2022 But Cointelegraph’s attempt to search for a Bitcoin address revealed a no-show on Google. Angel Investor Stephen Cole was not impressed, tweeting "Does Google not know about Bitcoin?" Cointelegraph also tried …
Adoption / Oct. 12, 2022
Vitalik Buterin reveals 3 ‘huge’ opportunities for crypto in 2023
Ethereum co-founder Vitalik Buterin has shared three “huge" opportunities yet to be realized in crypto, including mass crypto wallet adoption, inflation-resistant stablecoins, and Ethereum-powered website logins. During an interview with Bankless co-owner David Hoffman, Buterin shared his outlook for the crypto industry in 2023, responding to Hoffman’s raised concern that the “adoption wave” for decentralized applications is now over and that there’s “less opportunity” for developers to come in and build new decentralized applications. Buterin instead shrugged off the “limbo period” that Hoffman eluded to, firstly suggesting that more developments need to be made on cryptocurrency wallet infrastructure in order …
Adoption / Dec. 20, 2022