Malware

SeaFlower campaign distributes backdoored Web3 wallets for iOS and Android users

0

A technically sophisticated malware campaign tracked as SeaFlower was targeting Android and iOS users in an extensive campaign that mimics official cryptocurrency wallet websites intending to distribute backdoored apps that drain victims’ funds.

The malware campaign was uncovered by researchers from Confiant in March 2022. SeaFlower is a cluster of activity whose main objective is to modify Web3 wallets with backdoor code that ultimately exfiltrates the seed phrase.

The targeted apps include Android and iOS versions of Coinbase Wallet, MetaMask, TokenPocket, and imToken.

SeaFlower’s modus operandi involves setting up cloned websites that act as a conduit to download trojanized versions of the wallet apps that are virtually unchanged from their original counterparts except for the addition of new code designed to exfiltrate the seed phrase to a remote domain.

The malicious activity is also engineered to target iOS users by means of provisioning profiles that enable the apps to be sideloaded onto the devices.

The fake sites are promoted via search engine poisoning, attackers mainly targeted Baidu and other Chinese search engines.

The experts did not find a backdoored chrome extension delivered from these clone websites, all the links point to the real chrome extension in the Chrome Webstore.

This disclosure shows how threat actors are increasingly setting their sights on popular Web3 platforms in order to steal sensitive data and deceptively transfer virtual funds.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

New Syslogk Linux rootkit uses magic packets to trigger backdoor

Previous article

PM-Kisan website found leaking Aadhaar data

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *