Application security, Threat Intelligence

Hackers hijack Snapcraft apps for crypto theft

Cryptocurrency on Binance trading app, Bitcoin BTC with altcoin digital coin crypto currency, BNB, Ethereum, Dogecoin, Cardano, defi p2p decentralized fintech market

Per Tech Radar, hackers are exploiting dormant applications on the Snapcraft platform to distribute cryptocurrency-stealing malware, according to cybersecurity researchers from Anchore.

Attackers are targeting inactive Snapcraft applications by acquiring their expired domain names. This allows them to initiate password resets and gain unauthorized access to the app listings. Once control is established, they replace legitimate applications, often mimicking popular cryptocurrency wallets like Exodus, Ledger Live, and Trust Wallet, with malicious versions. These fake apps prompt users to enter their recovery phrases, which are then sent to the attackers. The malware displays an error message to the user, and by the time the deception is realized, the victim's cryptocurrency funds, in some cases up to $490,000, have been drained.

This ongoing campaign highlights a significant vulnerability in software distribution platforms where dormant accounts and expired domains can be exploited. Users are advised to exercise extreme caution when downloading applications, particularly those related to financial services and cryptocurrency, and to verify the legitimacy of the source.

Source: Tech Radar

You can skip this ad in 5 seconds