CybersecurityFintechNewswireTechnology

Must-Delete Apps on Your Smartphone Right Now

▼ Summary

– Over 20 malicious apps mimicking popular crypto wallets like SushiSwap and PancakeSwap were found on Google Play Store, tricking users into phishing scams.
– These apps, distributed via compromised developer accounts, steal mnemonic phrases to drain victims’ cryptocurrency funds.
– The apps embed Command and Control (C&C) URLs in privacy policies and use similar package names, indicating a coordinated campaign.
– Cyble researchers reported the apps to Google, with most removed before publication and the rest flagged for takedown.
– The campaign is dangerous due to its use of seemingly legitimate apps and a large-scale phishing infrastructure linked to over 50 domains.

Smartphone users should immediately check their devices for these dangerous apps that could drain cryptocurrency wallets. With millions of apps available across official stores, even trusted platforms like Google Play sometimes harbor malicious software. Recent findings reveal a sophisticated scam targeting crypto investors through fake wallet applications.

Security researchers at Cyble uncovered over 20 fraudulent apps disguised as legitimate cryptocurrency wallets, including imitations of SushiSwap, PancakeSwap, and Hyperliquid. These apps trick users into entering sensitive recovery phrases, which attackers then use to steal funds. The apps bypassed Google’s security checks by hijacking developer accounts that previously distributed genuine software.

The fake apps share alarming similarities—embedding malicious links in privacy policies and using nearly identical branding to fool victims. Once installed, they redirect users to phishing sites or display fake login screens to harvest wallet credentials. Cyble’s report lists the following counterfeit wallet names, urging users to delete them immediately:

  • Pancake Swap
  • Suiet Wallet
  • Hyperliquid
  • Raydium BullX
  • Crypto OpenOcean Exchange
  • Meteora Exchange
  • SushiSwap
  • Harvest Finance Blog

While Google has removed many of these apps, new variants continue appearing. The campaign leverages over 50 phishing domains, making detection difficult for standard security tools. Unlike traditional banking fraud, stolen cryptocurrency is nearly impossible to recover, emphasizing the need for extreme caution.

To stay protected, only download wallet apps from official developer websites and verify links before installing. Enable Google Play Protect to scan for threats automatically. If any suspicious apps match the names above, uninstall them without delay. Cybercriminals constantly refine their tactics, making vigilance essential for safeguarding digital assets.

(Source: FORBES)

Topics

malicious crypto wallet apps 95% phishing scams 90% cryptocurrency theft 90% google play store security 85% fake wallet applications 85% compromised developer accounts 80% user protection measures 80% command control cc urls 75% cyble researchers 70% google play protect 70%
Show More

The Wiz

Wiz Consults, home of the Internet is led by "the twins", Wajdi & Karim, experienced professionals who are passionate about helping businesses succeed in the digital world. With over 20 years of experience in the industry, they specialize in digital publishing and marketing, and have a proven track record of delivering results for their clients.
Close

Adblock Detected

We noticed you're using an ad blocker. To continue enjoying our content and support our work, please consider disabling your ad blocker for this site. Ads help keep our content free and accessible. Thank you for your understanding!