First CryptoCurrency Clipboard Hijacker Found on Google Play Store

- Advertisement -

Researchers last week found the first Android app on the Google Play store that monitors a device’s clipboard for Bitcoin and Ethereum addresses and swaps them for addresses under the attacker’s control. This allows the attackers to steal any payments you make without your knowledge that you sent it to the wrong address.

A malicious Android app called MetaMask was added to the Google Play store that pretended to be a mobile version of the legitimate service of the same name.  This app, though, was detected by ESET as malicious and when ESET Android security researcher Lukas Stefanko performed an analysis, it was discovered to be stealing a user’s cryptocurrency using two different attack methods.

The first attack method the app used was to attempt to steal the private keys and seeds of an Ethereum wallet when a user adds it to the app. When BleepingComputer analyzed the app’s APK file, we found that the app contains information that can be used to send this stolen data to a Telegram account.

Telegram Message Info
Telegram Message Info

Once a private key is entered, the app will combine the above information information along with the stolen private key and send it via Telegram to the attackers.  Stefanko confirmed that the attackers were using Telegram to receive the stolen keys and seeds.

Sending the stolen key via Telegram
Sending the stolen key via Telegram

The second attack method discovered by Stefanko was to monitor the device’s clipboard for Ethereum and Bitcoin addresses, and if one is detected, swap it out with a different address under the attacker’s control. As cryptocurrency addresses are composed of a long string of numbers and characters, it is hard to memorize them. Knowing this, attackers can swap a desired address with one under their control and have little chance of being detected.

Swapping Bitcoin and Ethereum addresses in clipboard
Swapping Bitcoin and Ethereum addresses in clipboard

When replacing addresses in the clipboard, the program will swap out a Bitcoin address with 17M66AG2uQ5YZLFEMKGpzbzh4F1EsFWkmA and an Ethereum address with 0xfbbb2EF692B5101f16d3632f836461904C761965.

Clipboard monitoring is not new and this attack method has been seen it numerous times already in Windows malware, browser extensions, and being sold on underground markets for Android. This is the first time, according to Stefanko, that one was detected on the Google Play store.

Thankfully, this particular app was not widespread and only had five installs. Stefanko told BleepingComputer that this was most likely because it was detected and reported only a few days after being uploaded to the Google Play store.



Previous Articles:

- Advertisement -
- Advertisement -
- Advertisement -

Latest

Solo Bitcoin Miner Hits Jackpot, Scores $266,000 With Single Block

A solo Bitcoin miner secured block 888,737 and earned approximately $266,000 in rewards, consisting of 3.125 BTC plus transaction fees.The miner reportedly used a...

Ex-SEC Official Rejects Crypto Regulatory Reform at SEC Roundtable

Former SEC official John Reed Stark opposes regulatory reform for cryptocurrencies at the SEC's first crypto roundtable.Stark argues crypto buyers are investors who need...

Open House Group Adds XRP, SOL, DOGE to Crypto Payment Options in Japan

Open House Group expands cryptocurrency payment options to include XRP, Solana, and Dogecoin alongside existing Bitcoin and Ethereum options.The company launches a Traditional Chinese...

Chainlink CCIP Breaks Vendor Lock-In Barrier for Cross-Chain Tokens

ChainLink CCIP provides token issuers with cross-chain functionality without being restricted to a single blockchain ecosystem.Cross-Chain Tokens (CCTs) enable seamless token movement across multiple...

Michael Saylor raises $722.5M for bitcoin buys at premium dividend rates

Strategy (formerly MicroStrategy) increased its fundraising from $500M to $722.5M but had to offer significantly more favorable terms to investors.The STRF preferred stock was...

Tether in Talks with Big Four Accounting Firm for Independent Audit

Tether is in discussions with one of the Big Four accounting firms to conduct an independent audit of its stablecoin reserves.The stablecoin issuer has...

SEC Finally Opens Door to Crypto Industry Collaboration on Regulations

SEC's Crypto Task Force, led by Commissioner Hester Peirce, held its first roundtable focused on developing a regulatory framework for digital assets.Acting Chairman Mark...

Coinbase in Advanced Talks to Acquire Crypto Derivatives Giant Deribit

Coinbase is in advanced discussions to acquire Deribit, potentially valuing the world's largest cryptocurrency derivatives exchange at $4-5 billion.The acquisition would expand Coinbase's derivatives...
- Advertisement -

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you are thinking of diving into the crypto-trading-space then you need to acquire some knowledge or else you are in danger of ''burning''...

Read Next
Recommended to you