Romance scammers exploit Apple's developer program to spread fake cryptocurrency apps
Full article818 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Swindlers have defrauded victims out of $1.4 million with the romance scam.
Fraudsters are using the promise of love to lure victims into downloading fake cryptocurrency trading apps and then stealing their funds, researchers at Sophos report.
The ongoing campaign, which researchers have dubbed “CryptoRom,” has targeted victims across Europe, the U.S. and Asia. In these scams, scammers use dating apps like Bumble, Tinder, and Grindr to build trust with a victim. They then move the conversation to a messaging app, where they ask victims to install a fake trading app.
Fraudsters convince victims to invest in the app, ultimately stealing the funds. Thieves have managed to swipe nearly $1.4 million with the ruse, according to an analysis of a bitcoin wallet one of the scammers used. Some 23,000 victims of romance scams reported more than $605 million in losses to the FBI in 2020.
The new findings underscore how fraudsters are turning to Apple’s developer programs in an attempt to evade the company’s policies against sideloading apps. To cut down on users downloading malicious apps, Apple only allows users to download apps from its official App Store. Attackers have found a way around this by using Apple’s program that allows developers to distribute apps that have not been approved by the App Store in a limited capacity for internal testing purposes.
Sophos researchers first reported a similar campaign targeting Android and iOS users in Asia in May. Researchers believe the fraudulent apps are related.
In order to trick the target into downloading the fake app, the attacker sends a link that opens a file which will prompt the user to “trust” the program. The device browser then sends the victim to a page designed to look like the App Store from which they can download the fake cryptocurrency app.
The malicious apps also give the thieves access to more than just bitcoin payments. At least one of the apps discovered by Sophos had an open directory that exposed a trove of personal information, including passport details and ID cards of nationals of Japan, Malaysia, South Korea and China.
Both international and U.S. law enforcement have warned about a massive spike in investment-related romance scams during the pandemic. Cryptocurrency scams using fake trading apps have also spiked in recent months.
While Apple has taken steps in recent years to reduce the abuse of its developer programs to spread malware, Sophos’s researchers predict that hackers will still continue to exploit the program for “targeted abuse.”
Criminals are also getting smarter at exploiting the system. In the set of attacks reported in May, the “CryptoRom” scammers used a program for individual developers that only allowed the app to use a limited number of devices.
Researchers found in the latest round of attacks that scammers are now using Apple’s enterprise program for developers, allowing them to spread the fraudulent apps to more devices. Moreover, paid commercial services offering enterprise certificates are making it easier for cybercriminals to simply direct victims to a new version of the app if Apple blocks an old signature.
Sophos shared the details of the malicious apps with Apple but did not hear back by the time of publication. Apple did not respond immediately to a request for comment from CyberScoop.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cryptocurrency-scam-cryptorom-ios-apple/