COMING SOON: A New Way to Earn Passive Income with DeFi in 2025 LEARN MORE

Internet security firm ESET exposes fake apps bypassing Google’s message restrictions

17450
fraud sa bitcoin scamfraud sa bitcoin scam

Contents

Share link:

In this post:

Analysts from the security firm ESET uncovered that fraudulent crypto apps have been employing a method to bypass authentication mechanisms on Google.

Google had recently imposed restrictions on SMS and calling for Android apps to prevent illicit firms from exploiting them.

The said apps, named BTCTurk Pro Beta, BtcTurk Pro Beta and BTCTURK PRO had created impressions of a legitimate Turkish crypto firm – BtcTurk – to gain access to the services.

Once the fraudulent versions of the BtcTurk apps are downloaded by a user, they ask for notification access from the user. Upon doing this, the apps can them peruse notifications from other apps on the user’s device and exploit them for their own financial gain.

“One of the positive effects of Google’s restrictions from March 2019 was that credential-stealing apps lost the option to abuse these permissions for bypassing SMS-based 2FA mechanisms. However, with the discovery of these fake apps, we have now seen the first malware sidestepping this SMS permission restriction,” said Lukáš Štefanko, a researcher from ESET.

The notification feature was implemented recently in the Jelly Bean 4.3 version of Android, which signifies that almost all current Android devices could fall prey to the scam’s methods of intrusion. The fraudulent BtcTurk apps could operate on a vast majority of Android devices of the day.

See also  Victim loses $2.5M in copy-paste scam twice

Despite this, the fake apps’ preferred technique of intrusion does come with its setbacks: The scam’s operators can only gain access to content that fits the text field.

This means that all text will not be included in the OTP. Messages that are shorter and more concise will likely be left out of the notification message.

KEY Difference Wire helps crypto brands break through and dominate headlines fast

Share link:

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Most read

Loading Most Read articles...

Stay on top of crypto news, get daily updates in your inbox

Editor's choice

Loading Editor's Choice articles...

- The Crypto newsletter that keeps you ahead -

Markets move fast.

We move faster.

Subscribe to Cryptopolitan Daily and get timely, sharp, and relevant crypto insights straight to your inbox.

Join now and
never miss a move.

Get in. Get the facts.
Get ahead.

Subscribe to CryptoPolitan