216.73.216.6

WalletConnect Scam: A Case Study in Crypto Drainer Tactics

· Published 26/09/2024 17:54 · Modified 26/09/2024 18:10

Export JSON

Essential information

Published
26/09/2024 17:54
Modified
26/09/2024 18:10
Tags
2024-09-26 android cryptocurrency mobile malware ms drainer
Related entities
6 observables, 12 techniques (mitre), 1 malware

Description

An investigation uncovered a malicious app on Google Play targeting mobile users to steal . The app, posing as a legitimate WalletConnect tool, used advanced evasion techniques to avoid detection for nearly five months. It achieved over 10,000 downloads through fake reviews and branding. The attackers used social engineering and a modern crypto drainer toolkit, stealing approximately $70,000 from over 150 victims. The malware, identified as , supports multiple blockchains and employs sophisticated methods to drain user wallets. This case highlights the growing sophistication of cybercriminal tactics in decentralized finance, emphasizing the need for vigilance among users and improved security measures in app stores.

External references