logo

Wallet Scam: A Case Study in Crypto Drainer Tactics

ID: 6f49efe2-9903-5aee-ae5a-e9b5fbdae12a

STIX ID: report--6f49efe2-9903-5aee-ae5a-e9b5fbdae12a

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2024-09-26

Date Updated: 2026-04-27

Author: alexeybu

...
...

Check Point Research uncovered a malicious Android app on Google Play that impersonated WalletConnect and delivered the MS Drainer web-based payload via deep links and obfuscated JavaScript; the campaign used evasion (redirects, user-agent checks, anti-debugging) to remain on the store for months, achieved over 10,000 downloads, victimized ~150 wallets and stole an estimated $70K in crypto. IOCs include domains (mestoxcalculator.com, web3protocol.online, connectprotocol.app, cakeserver.online) and three SHA256 hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.