A recent CYBLE research identified more than 20 fake apps on the Google Play Store that were stealing Crypto Keys by impersonating popular wallets like SushiSwap, PancakeSwap, Hyperliquid, and Raydium.
These malicious apps used phishing techniques to deceive users into entering a 12-word mnemonic phrase to access fake wallet interfaces, posing a significant threat to users' cryptocurrency security.
The hacker-controlled apps disguised themselves using stolen developer accounts, making it challenging for users to differentiate between legitimate and fake applications.
The malicious apps were found to use multiple deceptive strategies, including Command and Control URLs in their privacy policies, to remotely manage the stolen Crypto Keys and increase the difficulty of detection.