logo

Crypto Phishing Applications On The Play Store

ID: 30b980b2-ecec-58f9-8a5c-d4d235b3c669

STIX ID: report--30b980b2-ecec-58f9-8a5c-d4d235b3c669

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-07-17

...
...

Cyble Research identified an active campaign distributing 20+ malicious Android apps on Google Play that impersonate cryptocurrency wallets (PancakeSwap, SushiSwap, Raydium, etc.) to phish users' 12-word mnemonic phrases via WebView-loaded phishing pages and apps built with the Median framework; the operation uses shared infrastructure (50+ phishing domains on common IPs) and likely compromised developer accounts, and includes detailed IOCs (hashes, URLs, domains) with many apps removed from the Play Store but some remaining live.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.