Scammers Exploit Global Victims with Fake Trading Apps on Apple App Store and Google Play

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Beware of Fake Trading Apps Scam: Cybercriminals Targeting Victims Globally

A sophisticated fraud campaign utilizing fake trading apps has been uncovered by cybersecurity firm Group-IB, targeting unsuspecting victims on both the Apple App Store and Google Play Store. The operation, known as pig butchering, tricks individuals into investing in cryptocurrency or other financial instruments under false pretenses such as a romantic relationship or investment advice.

The global reach of this scheme spans across Asia-Pacific, Europe, the Middle East, and Africa, with victims falling prey to malicious apps built using the UniApp Framework, collectively known as UniShadowTrade. Despite being active since at least mid-2023, one of the apps managed to surpass Apple’s App Store review process, further legitimizing the scam.

Once installed, the apps prompt users to provide personal information and agree to terms and conditions before making investments. The cybercriminals then manipulate victims into depositing additional funds, promising high returns and displaying false gains to maintain the deception. However, when users attempt to withdraw their funds, they are coerced into paying more fees, ultimately leading to the loss of their investments.

The use of phishing websites and web-based applications has helped the perpetrators evade detection, with one such app distributing a URL hosted on a legitimate service to mask its malicious intent. Despite the fake trading apps being removed from the app stores, the threat actors continue to operate, emphasizing the importance of cybersecurity vigilance to thwart such scams.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...