logo

Fake Cryptocurrency Apps Steal User Data

ID: f49a12d7-98b1-557f-b6d2-faa603245d8c

STIX ID: report--f49a12d7-98b1-557f-b6d2-faa603245d8c

Feed Name: Binary Defense Blog

Threat Score
65/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Malicious Android apps impersonating the Poloniex exchange were distributed on the Google Play Store (one with ~5,000 downloads, another with ~500) and asked for Poloniex credentials on launch; if 2FA was not enabled attackers then phished victims' Gmail accounts, obtained mailbox permissions, removed evidence, and made unauthorized transactions. The apps were subsequently removed from the Play Store and users were advised to change passwords and uninstall the apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.