A technically sophisticated malware campaign tracked as SeaFlower was targeting Android and iOS users in an extensive campaign that mimics official cryptocurrency wallet websites intending to distribute backdoored apps that drain victims’ funds.
The malware campaign was uncovered by researchers from Confiant in March 2022. SeaFlower is a cluster of activity whose main objective is to modify Web3 wallets with backdoor code that ultimately exfiltrates the seed phrase.
The targeted apps include Android and iOS versions of Coinbase Wallet, MetaMask, TokenPocket, and imToken.
SeaFlower’s modus operandi involves setting up cloned websites that act as a conduit to download trojanized versions of the wallet apps that are virtually unchanged from their original counterparts except for the addition of new code designed to exfiltrate the seed phrase to a remote domain.
The malicious activity is also engineered to target iOS users by means of provisioning profiles that enable the apps to be sideloaded onto the devices.
The fake sites are promoted via search engine poisoning, attackers mainly targeted Baidu and other Chinese search engines.
The experts did not find a backdoored chrome extension delivered from these clone websites, all the links point to the real chrome extension in the Chrome Webstore.
This disclosure shows how threat actors are increasingly setting their sights on popular Web3 platforms in order to steal sensitive data and deceptively transfer virtual funds.














Comments