\"\"
<\/span><\/figcaption><\/figure>San Francisco: Scammers operating high-yielding investing scams called \"pig butchering\" have found a way to compromise Google Play<\/a> and Apple<\/a>'s App Store<\/a>, the official repositories for Android and iOS apps.

Pig butchering scams are those which involve fake websites, malicious advertising, and social engineering.

By adding fraudulent apps to official download platforms, scammers can gain a victim's trust easier, reports BleepingComputer.

According to
cybersecurity<\/a> company Sophos researchers, scammers are targeting victims on Facebook<\/a> or Tinder and convincing them to download the fraudulent apps and \"invest\" large sums of money in assets that appear to be real.

The
cybersecurity<\/a> firm observed that the campaign was undertaken by a China-based threat group named \"ShaZhuPan,\" which shows high organisational levels with distinct teams engaged in victim interactions, finance, franchise, and money laundering, according to the report.

The fraudsters appear to target male users over
Facebook<\/a> and Tinder using women's profiles with stolen images from other social media accounts.

Moreover, the report mentioned that the scammers after gaining the victims' trust, claim to have an uncle who works for a financial analysis firm and invite them to trade cryptocurrency through an app available on the
Google<\/a> Play or Apple App Store<\/a>.

Sophos discovered malicious apps called \"Ace Pro\" and \"MBM
BitScan<\/a>\" on the Apple<\/a> App Store<\/a>, and \"BitScan<\/a>\" on the Google<\/a> Play Store, which was used in the campaign.

The apps let the victim withdraw small amounts of cryptocurrency initially but then lock their accounts when larger amounts are involved.

Furthermore, in order to gain access to the App Store, the ShaZhuPan gang submits an app signed with a valid Apple certificate, which is a requirement for any code to be accepted into the iOS repository.

Until the app receives approval, it connects to a harmless server and behaves normally, said the report.

When the app passes the review, the developer changes the domain and connects to a malicious server.

Upon launching the app, the victim sees a cryptocurrency trading interface delivered by the malicious server; however, everything displayed is fake, except for the user's deposit, the report added.
<\/body>","next_sibling":[{"msid":97556764,"title":"Google's user choice billing system non-compliant with CCI's remedies: ADIF","entity_type":"ARTICLE","link":"\/news\/googles-user-choice-billing-system-non-compliant-with-ccis-remedies-adif\/97556764","category_name":null,"category_name_seo":"telecomnews"}],"related_content":[],"msid":97558540,"entity_type":"ARTICLE","title":"Scammers operating investing scams infiltrate Apple App Store, Google Play","synopsis":"According to cybersecurity company Sophos researchers, scammers are targeting victims on Facebook or Tinder and convincing them to download the fraudulent apps and \"invest\" large sums of money in assets that appear to be real.","titleseo":"telecomnews\/scammers-operating-investing-scams-infiltrate-apple-app-store-google-play","status":"ACTIVE","authors":[],"Alttitle":{"minfo":""},"artag":"IANS","artdate":"2023-02-02 20:33:43","lastupd":"2023-02-02 20:42:43","breadcrumbTags":["app store","apple app store","apple","bitscan","internet","facebook","google","google play","cybersecurity"],"secinfo":{"seolocation":"telecomnews\/scammers-operating-investing-scams-infiltrate-apple-app-store-google-play"}}" data-authors="[" "]" data-category-name="" data-category_id="" data-date="2023-02-02" data-index="article_1">

骗子操作投资诈骗渗透苹果应用商店,谷歌玩

根据网络安全公司Sophos的研究者,骗子是针对受害者在Facebook或易燃物,并说服他们下载欺诈性的应用和“投资”的大笔资金资产似乎是真实的。

  • 更新2023年2月2日08:42点坚持
旧金山:骗子操作高收益投资诈骗称为“猪屠宰”发现了一种妥协谷歌玩苹果应用程序商店,官方的存储库为Android和iOS应用程序。

猪屠宰诈骗是那些涉及虚假网站、恶意广告,和社会工程。

通过添加欺诈软件官方下载平台,骗子可以获得一个受害者的信任容易,BleepingComputer报告。

根据网络安全公司Sophos研究者,骗子是针对受害者脸谱网或易燃物和说服他们下载欺诈性的应用和“投资”的大笔资金资产似乎是真实的。

广告
网络安全公司发现运动是由一群中国威胁名叫“ShaZhuPan”,显示了高的组织水平与不同的团队从事受害者交互,金融,特许经营,和洗钱,根据该报告。

骗子似乎目标男性用户脸谱网并使用女性的易燃物从其他社交媒体账户资料用偷来的图像。

此外,该报告提到,骗子在获得受害者的信任,声称有一个叔叔在一家公司财务分析工作,并邀请他们贸易cryptocurrency通过一个应用程序可用谷歌玩或苹果应用商店

Sophos发现恶意程序称为“王牌专业”和“喜忧参半BitScan苹果 应用程序商店,“BitScan谷歌游戏商店,在运动中使用。

应用让患者取少量cryptocurrency最初然后当涉及大量锁自己的账户。

此外,为了获得App Store, ShaZhuPan帮派提交应用程序与一个有效的苹果签署证书,这是一个要求任何代码被接受到iOS库。

直到应用程序获得批准,它连接到一个无害的服务器和正常行为,报告说。

广告
当应用程序通过了审查,开发人员更改域和连接到一个恶意服务器。

在启动应用程序时,受害者看到cryptocurrency交易接口由恶意服务器;然而,一切都显示是假的,除了用户的存款,报告补充说。
  • 发布于2023年2月2日下午08:33坚持

加入2 m +行业专业人士的社区

订阅我们的通讯最新见解与分析。乐动扑克

下载ETTelec乐动娱乐招聘om应用

  • 得到实时更新
  • 保存您最喜爱的文章
扫描下载应用程序
\"\"
<\/span><\/figcaption><\/figure>San Francisco: Scammers operating high-yielding investing scams called \"pig butchering\" have found a way to compromise Google Play<\/a> and Apple<\/a>'s App Store<\/a>, the official repositories for Android and iOS apps.

Pig butchering scams are those which involve fake websites, malicious advertising, and social engineering.

By adding fraudulent apps to official download platforms, scammers can gain a victim's trust easier, reports BleepingComputer.

According to
cybersecurity<\/a> company Sophos researchers, scammers are targeting victims on Facebook<\/a> or Tinder and convincing them to download the fraudulent apps and \"invest\" large sums of money in assets that appear to be real.

The
cybersecurity<\/a> firm observed that the campaign was undertaken by a China-based threat group named \"ShaZhuPan,\" which shows high organisational levels with distinct teams engaged in victim interactions, finance, franchise, and money laundering, according to the report.

The fraudsters appear to target male users over
Facebook<\/a> and Tinder using women's profiles with stolen images from other social media accounts.

Moreover, the report mentioned that the scammers after gaining the victims' trust, claim to have an uncle who works for a financial analysis firm and invite them to trade cryptocurrency through an app available on the
Google<\/a> Play or Apple App Store<\/a>.

Sophos discovered malicious apps called \"Ace Pro\" and \"MBM
BitScan<\/a>\" on the Apple<\/a> App Store<\/a>, and \"BitScan<\/a>\" on the Google<\/a> Play Store, which was used in the campaign.

The apps let the victim withdraw small amounts of cryptocurrency initially but then lock their accounts when larger amounts are involved.

Furthermore, in order to gain access to the App Store, the ShaZhuPan gang submits an app signed with a valid Apple certificate, which is a requirement for any code to be accepted into the iOS repository.

Until the app receives approval, it connects to a harmless server and behaves normally, said the report.

When the app passes the review, the developer changes the domain and connects to a malicious server.

Upon launching the app, the victim sees a cryptocurrency trading interface delivered by the malicious server; however, everything displayed is fake, except for the user's deposit, the report added.
<\/body>","next_sibling":[{"msid":97556764,"title":"Google's user choice billing system non-compliant with CCI's remedies: ADIF","entity_type":"ARTICLE","link":"\/news\/googles-user-choice-billing-system-non-compliant-with-ccis-remedies-adif\/97556764","category_name":null,"category_name_seo":"telecomnews"}],"related_content":[],"msid":97558540,"entity_type":"ARTICLE","title":"Scammers operating investing scams infiltrate Apple App Store, Google Play","synopsis":"According to cybersecurity company Sophos researchers, scammers are targeting victims on Facebook or Tinder and convincing them to download the fraudulent apps and \"invest\" large sums of money in assets that appear to be real.","titleseo":"telecomnews\/scammers-operating-investing-scams-infiltrate-apple-app-store-google-play","status":"ACTIVE","authors":[],"Alttitle":{"minfo":""},"artag":"IANS","artdate":"2023-02-02 20:33:43","lastupd":"2023-02-02 20:42:43","breadcrumbTags":["app store","apple app store","apple","bitscan","internet","facebook","google","google play","cybersecurity"],"secinfo":{"seolocation":"telecomnews\/scammers-operating-investing-scams-infiltrate-apple-app-store-google-play"}}" data-news_link="//www.iser-br.com/news/scammers-operating-investing-scams-infiltrate-apple-app-store-google-play/97558540">