Google’s official Play Store has been caught hosting malicious apps that targeted Android users with an interest in cryptocurrencies, researchers reported on Thursday.
In all, researchers with security provider ESET recently discovered two fraudulent digital wallets. The first, called Coin Wallet, let users create wallets for a host of different cryptocurrencies. While Coin Wallet purported to generate a unique wallet address for users to deposit coins, the app in fact used a developer-owned wallet for each supported currency, with a total of 13 wallets. Each Coin Wallet user was assigned the same wallet address for a specific currency.
“The app claims it lets users create wallets for various cryptocurrencies,” ESET Malware Researcher Lukas Stefanko wrote in a blog post. “However, its actual purpose is to trick users into transferring cryptocurrency into the attackers’ wallets—a classic case of what we named wallet address scams in our previous research of cryptocurrency-targeting malware.”