Daily Mail PH

Monday, November 13, 2023

[New post] Chinese hackers use fake Skype app to target crypto users in new phishing scam

Site logo image Crypto Breaking News posted: "A new phishing scam has emerged in China that uses a fake Skype video app to target crypto users.According to a report by crypto security analytics firm SlowMist, the Chinese hackers behind the phishing scam used China's ban on international applicat" Crypto Breaking News

Chinese hackers use fake Skype app to target crypto users in new phishing scam

Crypto Breaking News

Nov 13

A new phishing scam has emerged in China that uses a fake Skype video app to target crypto users.

According to a report by crypto security analytics firm SlowMist, the Chinese hackers behind the phishing scam used China's ban on international applications as the basis of their fraud, with many mainland users often searching for these banned applications via third-party platforms.

Social media applications such as Telegram, WhatsApp and Skype are some of the most common applications searched for by mainland users, so scammers often use this vulnerability to target them with fake, cloned applications containing malware developed to attack crypto wallets.

Baidu search results for Skype. Source: Baidu

In its analysis, the SlowMist team found that the recently created fake Skype application displayed version 8.87.0.403, while the latest official version of Skype is 8.107.0.215. The team also discovered that the phishing back-end domain "bn-download3.com" impersonated the Binance exchange on Nov. 23, 2022, later changing to mimic a Skype back-end domain on May 23, 2023. The fake Skype app was first reported by a user who lost "a significant amount of money" to the same scam.

The fake app's signature revealed that it had been tampered with to insert malware. After decompiling the app, the security team discovered a modified commonly used Android network framework, "okhttp3," to target crypto users. The default okhttp3 framework handles Android traffic requests, but the modified okhttp3 obtains images from various directories on the phone and monitors for any new images in real time.

The malicious okhttp3 requests users to give access to internal files and images, and as most social media applications ask for these permissions anyway, they often don't suspect any wrongdoing. Thus, the fake Skype immediately begins uploading images, device information, user ID, phone number and other information to the back end.

Once the fake app has access, it continuously looks for images and messages with Tron (TRX) and Ether (ETH)-like address format strings. If such addresses are detected, they are automatically replaced with malicious addresses pre-set by the phishing gang.

Fake Skype app back end. Source: Slowmist

During SlowMist testing, it was found that the wallet address replacement had stopped, with the phishing interface's back end shut down and no longer returning malicious addresses.

Related: 5 sneaky tricks crypto phishing scammers used last year

The team also discovered that a Tron chain address (TJhqKzGQ3LzT9ih53JoyAvMnnH5EThWLQB) had received approximately 192,856 Tether (USDT) by Nov. 8, with a total of 110 transactions made to the address. At the same time, another ETH chain address (0xF90acFBe580F58f912F557B444bA1bf77053fc03) received approximately 7,800 USDT in 10 transactions.

The SlowMist team flagged and blacklisted all wallet addresses linked to the scam.

Magazine: Thailand's $1B crypto sacrifice, Mt. Gox final deadline, Tencent NFT app nixed

Source: Cointelegraph.com


Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://www.cryptobreaking.com/chinese-hackers-use-fake-skype-app-to-target-crypto-users-in-new-phishing-scam/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at November 13, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Rappler x Linya-Linya campaign launch kasama sina Raco Ruiz, Ansis Sy, Monica Cruz

Tara na sa Rappler x Linya-Linya campaign launch!   06 January 2026 View in Browser       Pagbati!   Isang bagong taon ang sumasalubon...

  • [New post] Achieve Data Sovereignty through Omnisphere
    Crypto Breaking News posted: "Web 3.0 is one of the biggest buzzwords flying around the world of social media this year. An...
  • [New post] Tuesday’s politics thread is trying to stay positive.
    SheleetaHam posted: " Even though I just finished the latest Opening Arguments podcast about how Roe v. Wade is toast, and ...
  • [New post] Is XRP going to take the Crypto market by storm
    admin posted: "Is XRP going to take the Crypto market by storm While the SEC has been going after Ripple in court the XRP b...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • January 2026 (1)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.