Wallet Scam: A Case Study in Crypto Drainer Tactics
ID: 6f49efe2-9903-5aee-ae5a-e9b5fbdae12a
STIX ID: report--6f49efe2-9903-5aee-ae5a-e9b5fbdae12a
Feed Name: Check Point Research
Check Point Research uncovered a malicious Android app on Google Play that impersonated WalletConnect and delivered the MS Drainer web-based payload via deep links and obfuscated JavaScript; the campaign used evasion (redirects, user-agent checks, anti-debugging) to remain on the store for months, achieved over 10,000 downloads, victimized ~150 wallets and stole an estimated $70K in crypto. IOCs include domains (mestoxcalculator.com, web3protocol.online, connectprotocol.app, cakeserver.online) and three SHA256 hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
