• Latest
  • Trending
Lookalike Telegram and WhatsApp Websites Distributing… – The Hacker News

Lookalike Telegram and WhatsApp Websites Distributing… – The Hacker News

18.03.2023
Flash Sale: Get Microsoft Office 2021 for Mac or Windows for… – Macworld

Pay $40 for lifetime access to Microsoft Office – PCWorld

24.03.2023
Teddy Sheringham says Declan Rice would improve Arsenal and ‘could come into any team’

Teddy Sheringham says Declan Rice would improve Arsenal and ‘could come into any team’

24.03.2023
Skai Jackson recalls receiving a note from Justin Bieber: ‘It’s been ten years, I still have it’ – Yahoo News

Skai Jackson recalls receiving a note from Justin Bieber: ‘It’s been ten years, I still have it’ – Yahoo News

24.03.2023
Drug-resistant bacteria linked to recalled eye drops cost fire captain the sight of one eye – Reuters

Drug-resistant bacteria linked to recalled eye drops cost fire captain the sight of one eye – Reuters

24.03.2023
Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

24.03.2023
macOS Compatibility: Can Your Mac Run Ventura?  – Macworld

macOS Compatibility: Can Your Mac Run Ventura? – Macworld

24.03.2023
Taylor Swift The Eras Tour setlist: The 44 songs played by Taylor… – PopBuzz

Taylor Swift The Eras Tour setlist: The 44 songs played by Taylor… – PopBuzz

24.03.2023
Ben Affleck reveals he and Jennifer Lopez are ‘Yellowstone’ fans – Gold Derby

Ben Affleck reveals he and Jennifer Lopez are ‘Yellowstone’ fans – Gold Derby

24.03.2023
Markquis Nowell sets NCAA Tournament assist mark, leads K-State in Elite 8 – ESPN

Markquis Nowell sets NCAA Tournament assist mark, leads K-State in Elite 8 – ESPN

24.03.2023
GLX Holding AS: Successful Placement of 4-Year Sustainable Bonds – Marketscreener.com

INDIA BONDS-Indian bond yields little changed as traders await new clues – Marketscreener.com

24.03.2023
PayPal Launches Passkey Logins for Android Web in US – Yahoo Entertainment

PayPal Launches Passkey Logins for Android Web in US – Yahoo Entertainment

24.03.2023
Channel 10 star Angela Bishop gives Hugh Grant a surprise gift after his awkward Oscars interview

Channel 10 star Angela Bishop gives Hugh Grant a surprise gift after his awkward Oscars interview

24.03.2023
Friday, March 24, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Economics » Lookalike Telegram and WhatsApp Websites Distributing… – The Hacker News

Lookalike Telegram and WhatsApp Websites Distributing… – The Hacker News

18/03/2023 23:04:42
in Economics
0

Related posts

Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

24.03.2023
GLX Holding AS: Successful Placement of 4-Year Sustainable Bonds – Marketscreener.com

INDIA BONDS-Indian bond yields little changed as traders await new clues – Marketscreener.com

24.03.2023

March 17, 2023Ravie LakshmananCryptocurrency / Mobile Security

Copycat websites for instant messaging apps such as Telegram and WhatApp are used to distribute trojanized versions and infect Android and Windows users with cryptocurrency clipper malware.

“All are after victims’ cryptocurrency funds, with several targeting cryptocurrency wallets,” ESET researchers Lukáš Štefanko and Peter Strýček said in a new analysis.

While the first instance of clipper malware on the Google Play Store dates back to 2019, the development marks the first time Android-based clipper malware has been integrated into instant messaging apps.

“Additionally, some of these apps use Optical Character Recognition (OCR) to recognize text from screenshots stored on compromised devices, which is another first for Android malware,” the Slovak company added. of cybersecurity.

The chain of attack begins with unsuspecting users clicking on fraudulent ads on Google search results that lead to hundreds of sketchy YouTube channels, which then direct them to similar Telegram and WhatsApp websites.

What is new in the latest batch of clipper malware is that it is able to intercept a victim’s chats and replace all cryptocurrency wallet addresses sent and received with addresses controlled by threat actors.

Another group of clipper malware uses OCR to find and steal seed phrases by exploiting a legitimate machine learning plugin called ML Kit on Android, thereby emptying wallets.

A third cluster is designed to keep an eye on Telegram conversations for certain Chinese cryptocurrency-related keywords, both hard-coded and received from a server, and if so, exfiltrate the full message , along with username, group, or channel name, to a remote server.

Telegram and WhatsApp

Finally, a fourth set of Android clippers come with capabilities to change the wallet address as well as collect device information and Telegram data such as messages and contacts.

Rogue Android APK package names are listed below –

  • org.telegram.messenger
  • org.telegram.messenger.web2
  • org.tgplus.messenger
  • io.busniess.va.whatsapp
  • com.whatsapp

ESET said it also found two Windows-based clusters, one designed to swap wallet addresses and a second group that distributes Remote Access Trojans (RATs) instead of clippers to take control of infected hosts and perpetrate crypto theft.

ONLINE SEMINAR

Discover the hidden dangers of third-party SaaS applications

Are you aware of the risks associated with third-party access to your company’s SaaS applications? Join our webinar to learn more about the types of permissions granted and how to minimize risk.

RESERVE YOUR PLACE

All RAT samples analyzed are based on the publicly available Gh0st RAT, except for one, which uses more anti-parsing runtime checks when running and uses the HP socket library to communicate with his server.

It should also be noted that these clusters, although following an identical modus operandi, represent disparate sets of activities likely developed by different threat actors.

The campaign, like a similar malicious cyber operation that came to light last year, is aimed at Chinese-speaking users, mainly motivated by the fact that Telegram and WhatsApp are blocked in the country.

“People who want to use these services must resort to indirect means to obtain them,” the researchers said. “Unsurprisingly, this presents a great opportunity for cybercriminals to abuse the situation.”

Did you find this article interesting ? follow us on Twitter  and LinkedIn to read more exclusive content we publish.



Related

Previous Post

How to get Microsoft Word for free on Mac – Macworld

Next Post

Three children, ages 1-7, die after house fire early Saturday morning, Baltimore Fire Department says – Baltimore Sun

Related Posts

Venezuela halts nearly all oil exports due to payment probe – OilPrice.com
Economics

Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

24.03.2023
0

Venezuela's crude oil exports have all but dried up as the government investigates oil contracts with a mountain of unpaid...

Read more
GLX Holding AS: Successful Placement of 4-Year Sustainable Bonds – Marketscreener.com

INDIA BONDS-Indian bond yields little changed as traders await new clues – Marketscreener.com

24.03.2023
Americans will dump up to $1.1 trillion in stocks this year and move the money to credit and money market funds, Goldman says.  – Market Watch

Americans will dump up to $1.1 trillion in stocks this year and move the money to credit and money market funds, Goldman says. – Market Watch

24.03.2023

Argo Blockchain PLC Announces Grant of Equity Awards and PDMR Notifications – Yahoo Finance

24.03.2023

Corruption and deep disparities mark Iraq’s oil legacy after 2003 – Honolulu Star-Advertiser

24.03.2023

Hong Kong on the lookout for any spillover from US regional banks – Firstpost

24.03.2023
Load More
Next Post
Three children, ages 1-7, die after house fire early Saturday morning, Baltimore Fire Department says – Baltimore Sun

Three children, ages 1-7, die after house fire early Saturday morning, Baltimore Fire Department says - Baltimore Sun

Recent Posts

  • Pay $40 for lifetime access to Microsoft Office – PCWorld
  • Teddy Sheringham says Declan Rice would improve Arsenal and ‘could come into any team’
  • Skai Jackson recalls receiving a note from Justin Bieber: ‘It’s been ten years, I still have it’ – Yahoo News
  • Drug-resistant bacteria linked to recalled eye drops cost fire captain the sight of one eye – Reuters
  • Venezuela halts nearly all oil exports due to payment probe – OilPrice.com

Archives

  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • 0
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.