Fortune | FORTUNE 2024年10月19日
Fake trading apps on Google Play and App Store linked to global ‘pig butchering’ scam
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

网络犯罪分子利用虚假交易App进行‘杀猪盘’诈骗。这种投资欺诈形式先骗取受害者信任,让其在假平台上大量投资,然后卷款。Group-IB发现多个假App,它们伪装成交易平台,通过社交平台诱骗用户下载,获取敏感信息并骗其投资,且此类诈骗在多地均有受害者,相关假App虽被部分下架,但仍通过钓鱼网站传播。

🎯网络犯罪分子开展全球‘杀猪盘’活动,通过虚假交易App诈骗,先与受害者建立信任,再骗取投资,此骗局与加密货币有关且伪装巧妙,四年间受害者损失超750亿美元。

💻自五月起,Group-IB发现多个假交易App在谷歌和苹果应用商店伪装成交易平台,被认定为UniShadowTrade恶意软件家族成员,由UniApp Framework构建,通过社交工程策略在约会和社交平台上寻找目标。

🚫Group-IB发现的假App有的声称可用于数学公式和图形计算,诱导用户注册并披露敏感信息后要求存款,用户无法提现;有的伪装成分享股票新闻的App,有上千次下载量,虽被应用商店下架,但仍通过钓鱼网站传播。

🌍Group-IB称在亚太、欧洲、中东和非洲地区均发现了‘杀猪盘’受害者,此类诈骗是恶意攻击者进行投资相关犯罪的众多手段之一。

New research from cybersecurity company Group-IB shows that cybercriminals have been using phony trading apps to swindle unsuspecting individuals as part of a global “pig butchering” campaign.Pig butchering is a form of investment fraud where scammers persuade their victims into making large investments on fake trading platforms. The scheme—which is commonly associated with cryptocurrency and is surprisingly vegan-friendly—refers to how scammers build trust with their victims before later draining them of their investments. The ruse has proven to be a lucrative cyber threat, with researchers from the University of Texas at Austin estimating that pig butchering scammers have stolen more than $75 billion from victims in the last four years.Since May, Group-IB analysts have identified several fake mobile applications that have been disguised as trading platforms on the Google Play and Apple App Store, and used as part of the global scheme. The cybersecurity company, which was founded in Russia but shifted its headquarters to Singapore in 2019, has classified the fraudulent apps as members of the UniShadowTrade malware family and said the mobile applications were built using the UniApp Framework.Hoodwinked! While Group-IB was unable to pinpoint how cybercriminals are going about targeting their pig butchering victims, the report suggested it is most likely through social engineering tactics on dating and social networking platforms. After building a relationship with their victims, malicious actors are then able to convince them to download seemingly legit applications to execute their crime.One example of a fake app discovered by Group-IB deceived users with a description that claimed it could be used for “algebraic mathematical formulas and 3D graphics volume area calculations.” Users who downloaded the app were prompted to make an account and disclose sensitive information, before being instructed to make a deposit. The cybercriminal is then able to convince the victim to continue investing money on the platform, which they are unable to withdraw.The app has since been removed from the App Store, but Group-IB claims that cybercriminals have continued to circulate it to both Apple and Android users through phishing websites.Another bogus app discovered by Group-IB on the Google Play Store masqueraded as an application that shared stock-related news. The app racked up more than a thousand downloads before being removed by the app store.Group-IB claims it was able to identify pig butchering victims across the Asia-Pacific, European, and Middle East and Africa regions.Zoom out. The recently discovered tactic joins the slew of strategies malicious actors are using to perform investment-related crimes. IT Brew has previously reported that cybercriminals are also sending their victims to their local Bitcoin ATM to secretly drain their accounts and impersonating the web pages of common retail brands as part of their crypto fraud gambits.Read more from Morning Brew

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络诈骗 虚假交易App 杀猪盘 Group-IB
相关文章