Fake Finance Apps Focus On Theft

Criminals have published hundreds of bogus banking, finance, and crypto-currency apps that steal your money. A team of researchers at Sophos say they have identified as many as 167 fake banking, trading and crypto-currency apps that criminals are using to steal money and financial information from unsuspecting users.

These fraudulent applications are aimed at exploiting the increased interest in trading apps, driven by the recent significant rise in the value of crypto-currencies.

These are also led by interest in low-cost or free stock trading driven by stories like that of the recent social-media driven speculation in GameStop stock where there has been an extraordinary rise in the share price of the ailing video games retailer GameStop amid a surge of bets by small investors. 

The researchers discovered the fake apps while investigating another bogus mobile trading app, which presented itself as one linked to Asian gold trading firm Goldenway Group. The cyber criminals operating these fake Android and iOS apps used counterfeit websites, social engineering techniques, and a fake iOS App Store download page to trick potential victims into believing that they were downloading and installing a legitimate app. In one case, scammers targeted a user through a dating website, where they tricked him into downloading a fake crypto-currency trading app. They avoided requests for face-to-face meetings, citing the pandemic, but encouraged the user to buy crypto-currency and transfer it into their wallet. When the victim tried to close the account or withdraw money, the scammers blocked account access.

Sophos said all the fraudulent apps it identified use a common server and similar designs, suggesting that a single group or entity is responsible.

Some apps offered a customer support chat option, and were observed to be using near-identical language when contacted.
During investigation of one of the apps Sophos encountered a server which was hosting hundreds of fake trading, banking, foreign exchange, and crypto currency apps. 

Among them were counterfeit apps impersonating major financial firms and popular crypto-currency trading platforms, including Barclays, Gemini, Bitwala, Kraken, Binance, BitcoinHK, Bittrex, BitFlyer, and TDBank. Each of these fake apps had a dedicated website tailored to the impersonated brand to better fool potential victims. "People trust the brands and people they know, or think they know, and the operators behind these fake trading and crypto-currency scams ruthlessly take advantage of that," said Jagadeesh Chandraiah, a senior threat researcher at Sophos.

To protect themselves against this kind of scam, Chandraiah advised mobile users to only install apps from trusted sources, like Apple and Google's official app stores. He also stressed the need for people to be cautious about websites or apps that claim unrealistically high returns on investments. "If something seems too good to be true - promised high returns on investments, or professional-looking dating profiles asking to transfer money or crypto assets - it's likely a scam," Chandraiah said.

Unverified and third-party mobile apps are a long-standing and growing security issue. Last year, researchers reported about two malware campaigns targeting Android users with apps that claimed to optimise smartphone performance but actually delivered malware. 

Also last year, researchers at Kaspersky uncovered a cyber espionage campaign that had used the Google Play Store to distribute malware for about four years, proving that even the official app stores aren't completely safe.
Dubbed 'PhantomLance', the campaign was linked to threat group APT32 or OceanLotus, which is thought to have backed by the Vietnamese government.

Innocent people tend to put trust in things that are presented by someone they think they know.  And since these fake applications impersonate well-known apps from all over the world, the fraud is that more believable. If  something seems too good to be true, promised high returns on investments, or professional-looking dating profiles asking to transfer money or crypto assets and this is probably a scam.

Romance scams involve people being duped into sending money to criminals who go to great lengths to gain their trust and convince them that they are in a genuine relationship. They use language to manipulate, persuade and exploit so that requests for money do not raise alarm bells. These requests might be highly emotive, such as criminals claiming they need money for emergency medical care, or to pay for transport costs to visit the victim if they are overseas. Scammers will often build a relationship with their victims over time.

To avoid falling prey to such malicious apps, users should only install apps from trusted sources such as Google Play and Apple’s app store. 

How to Report Fraud

If you think you have been a victim of a romance scam, do not feel ashamed or embarrassed, you are not alone. Contact your bank immediately and in the United Kingdom report it to Action Fraud on 0300 123 2040.  

Sophos:       Coin Market Cap:          Computing:       Guardian:       Action Fraud

You Might Also Read:

Online Fraud Costs British Investors £63m:

 

« Microsoft’s Defensive Playbook
Identifying & Minimizing Security Vulnerabilities For Your Organization »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Visual Guard

Visual Guard

Visual Guard is a modular solution covering most application security requirements, from application-level security systems to Corporate Identity and Access Management Solutions.

Sera-Brynn

Sera-Brynn

Sera-Brynn is one of the highest-ranked, pure-play cybersecurity compliance and advisory firms in the world.

Safe Security

Safe Security

Safe Security (formerly Lucideus) provides Cyber risk assessment services and platforms to multiple Fortune 500 companies and governments across the globe.

GuardSI

GuardSI

GuardSI was created to protect companies from growing threats to security such as fraud, hacking, internal theft, accidents and human mistakes that can directly affect the business.

ANSI National Accreditation Board (ANAB)

ANSI National Accreditation Board (ANAB)

ANAB is the largest accreditation body in North America. The directory of members provides details of organisations offering certification services for cybersecurity related standards.

Deep Mirror Automotive Cybersecurity

Deep Mirror Automotive Cybersecurity

Deep Mirror Automotive Cybersecurity make Cars & Infrastructures Cybersecure.

Liquid Technology

Liquid Technology

Liquid Technology provide DOD- and NIST-compliant data destruction and EPA-compliant e-waste disposal and recycling services throughout North America, Europe and Asia.

Tesserent

Tesserent

Tesserent (formerly Pure Security) is a full-service cybersecurity solutions provider. We partner with clients across Australia and New Zealand in the protection of their digital assets.

Antares NetlogiX

Antares NetlogiX

Antares Netlogix are a leading Austrian service provider for IT security, critical infrastructures and managed security services.

Secureframe

Secureframe

Companies from startups to enterprises use Secureframe to automate SOC 2 and ISO 27001 compliance, complete audits, and continuously monitor their security.

Input Output (IOHK)

Input Output (IOHK)

IOHK is one of the world's pre-eminent blockchain infrastructure research and engineering companies.

Tsaaro Academy

Tsaaro Academy

Tsaaro Academy is a unique privacy certification training platform and here you earn a privacy certification CEH, CISM and DPO from India’s No.1 Privacy training platform.

Segra

Segra

Segra owns and operates one of the nation’s largest fiber networks and provides best-in-class broadband and data security solutions throughout the Southeast and Mid-Atlantic.

Cyber Proud

Cyber Proud

Cyber proud is leading a talent revolution to promote and create an inclusive skilled cyber workforce.

Xmore AI

Xmore AI

Xmore AI, an emerging disruptor in our incubation, is building AI models to optimize and secure IT with the mission of increasing efficiency and reducing costs.

Bureau

Bureau

Bureau is a no-code, identity decisioning platform that offers businesses the complete range of risk, compliance and ongoing fraud monitoring solutions innovated with AI.