Bitcoin
Bitcoin (BTC)
$63,197.00 -0.60963
Bitcoin price
Ethereum
Ethereum (ETH)
$3,275.92 0.32859
Ethereum price
BNB
BNB (BNB)
$599.83 0.28446
BNB price
Solana
Solana (SOL)
$138.25 -3.02309
Solana price
XRP
XRP (XRP)
$0.5128430 -1.52679
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000243 -2.33898
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000072 -1.26251
Pepe price
Bonk
Bonk (BONK)
$0.0000246 -2.98989
Bonk price
Bitcoin
Bitcoin (BTC)
$63,197.00 -0.60963
Bitcoin price
Ethereum
Ethereum (ETH)
$3,275.92 0.32859
Ethereum price
BNB
BNB (BNB)
$599.83 0.28446
BNB price
Solana
Solana (SOL)
$138.25 -3.02309
Solana price
XRP
XRP (XRP)
$0.5128430 -1.52679
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000243 -2.33898
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000072 -1.26251
Pepe price
Bonk
Bonk (BONK)
$0.0000246 -2.98989
Bonk price
Bitcoin
Bitcoin (BTC)
$63,197.00 -0.60963
Bitcoin price
Ethereum
Ethereum (ETH)
$3,275.92 0.32859
Ethereum price
BNB
BNB (BNB)
$599.83 0.28446
BNB price
Solana
Solana (SOL)
$138.25 -3.02309
Solana price
XRP
XRP (XRP)
$0.5128430 -1.52679
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000243 -2.33898
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000072 -1.26251
Pepe price
Bonk
Bonk (BONK)
$0.0000246 -2.98989
Bonk price
Bitcoin
Bitcoin (BTC)
$63,197.00 -0.60963
Bitcoin price
Ethereum
Ethereum (ETH)
$3,275.92 0.32859
Ethereum price
BNB
BNB (BNB)
$599.83 0.28446
BNB price
Solana
Solana (SOL)
$138.25 -3.02309
Solana price
XRP
XRP (XRP)
$0.5128430 -1.52679
XRP price
Shiba Inu
Shiba Inu (SHIB)
$0.0000243 -2.33898
Shiba Inu price
Pepe
Pepe (PEPE)
$0.0000072 -1.26251
Pepe price
Bonk
Bonk (BONK)
$0.0000246 -2.98989
Bonk price
SirWin
SirWin
SirWin

Chinese hackers target crypto investors with fake Skype

chinese-hackers-target-crypto-investors-with-fake-skype
Edited by
News
Chinese hackers target crypto investors with fake Skype

The fake Skype application is being heavily distributed on the Chinese internet, the SlowMist Security Team has learned.

As many international marketplaces are inaccessible within China due to local regulations, bad actors are actively exploiting this gap, flooding the market with phishing applications targeting crypto investors.

According to a blockchain security firm SlowMist, a group of Chinese scammers has recently started distributing a fake version of Skype — version 8.87.0.403 — for Android devices among multiple local marketplaces, such as 51pgzs, siyuetian, and others. They lure victims to believe they downloaded a legit version of the video chat application.

Chinese hackers target crypto investors with fake Skype - 1
Fake Skype application for Android on a Chinese marketplace | Source: Medium

Once the malicious application is installed, it obtains images from various directories on the Android phone and monitors in real-time for any new images. All the images stored on the victim’s device are then uploaded to the phishing gang’s backend interface.

Analysts at SlowMist also learned that the gang behind the fake Skype application also targeted users in 2022 with its scam version of Binance, pointing out that both malicious applications have similar backend domain “bn-download3[dot]com.”

“Further analysis revealed that ‘bn-download[number]’ is a series of fake domains used by this phishing gang specifically for Binance phishing, indicating that this gang is a repeat offender targeting Web3 specifically.”

SlowMist

In addition to images, the malicious application sends data to bad actors’ backend, such as device information, user ID, and phone number. To make things worse, the fake Skype even monitors incoming and outgoing messages to see if they include TRON or Ethereum-type address format strings to replace them with addresses pre-made by the scammers automatically.

Chinese hackers target crypto investors with fake Skype - 2
A USDT wallet on TRON belonging to a malicious Chinese gang | Source: Medium

SlowMist found out that the TRON chain address, which belongs to the scammers, had received nearly $193,000 in Tether (USDT) with 110 transactions, noting that funds are still coming in as the most recent transaction was on Nov 8, 2023. In general, most of the stolen funds were laundered through BitKeep’s Swap service, with the transaction fees covered by a user registered on the OKX crypto exchange, SlowMist emphasized.