Cointelegraph
DOGE$0.06939 0.80%
TRX$0.3295 0.45%
LINK$8.28 2.83%
ZEC$475.65 6.91%
ADA$0.1620 3.48%
XRP$1.08 2.23%
ETH$1,854.45 1.88%
BTC$63,956.12 2.16%
XMR$367.91 3.21%
BNB$565.00 0.67%
XLM$0.1770 3.56%
SOL$73.78 2.71%
HYPE$57.15 2.99%
Written by Joeri CantcontributorReviewed by Igor Belkinformer editor

Report: Android Vulnerability Allows Hackers to Steal Crypto Wallet Info

Latest NewsPublishedDec 3, 2019

Security researchers have uncovered a vulnerability that could allow hackers to access private data on any Android phone, including login credentials to crypto wallets.

report-android-vulnerability-allows-hackers-to-steal-crypto-wallet-info

Promon security researchers have uncovered a vulnerability that could allow cybercriminals to access private data on any Android phone.

500 most popular apps are at risk

On Dec. 2, the Norwegian app security firm Promon revealed the discovery of a dangerous Android vulnerability called StrandHogg, which has reportedly infected all versions of Android and has put the top 500 most popular apps at risk. Promon CTO Tom Lysemose Hansen commented:

“We have tangible proof that attackers are exploiting StrandHogg in order to steal confidential information. The potential impact of this could be unprecedented in terms of scale and the amount of damage caused because most apps are vulnerable by default and all Android versions are affected.”

How does StrandHogg work?

StrandHogg poses as any other app on the infected device and tricks users into believing that they are using a legitimate app. The vulnerability then allows malicious apps to phish users’ credentials by displaying a malicious and fake version of a login screen. The report reads:

“When the victim inputs their login credentials within this interface, sensitive details are immediately sent to the attacker, who can then login to, and control, security-sensitive apps.”

Aside from stealing personal information like crypto wallet login credentials, StrandHogg can also reportedly listen to the user through their microphone, read and send text messages, and access all private photos and files on the device, among other nefarious exploits.

The Promon researchers further pointed out that they have disclosed their findings to Google last Summer. However, while Google did remove the affected apps, it does not appear as if the vulnerability has been fixed for any version of Android.

Criminals use YouTube to install cryptojacking malware

In November, the Slovakian software security firm Eset uncovered that cyber criminals behind the Stantinko botnet have been distributing a Monero (XMR) cryptocurrency mining module via Youtube. The major antivirus software supplier reported that the Stantinko botnet operators had expanded their criminal reach from click fraud, ad injection, social network fraud and password stealing attacks, into installing crypto mining malware on victims’ devices using Youtube.

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject