Close Menu
Technology News & TrendsTechnology News & Trends

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Spies hack Wi-Fi networks in far-off land to launch attack on target next door

    December 2, 2024

    QNAP firmware update leaves NAS owners locked out of their boxes

    December 2, 2024

    Found on VirusTotal: The world’s first UEFI bootkit for Linux

    December 2, 2024
    Facebook X (Twitter) Instagram
    Technology News & TrendsTechnology News & Trends
    Facebook X (Twitter) Instagram
    SUBSCRIBE
    • Home
    • Biz & IT

      Spies hack Wi-Fi networks in far-off land to launch attack on target next door

      December 2, 2024

      QNAP firmware update leaves NAS owners locked out of their boxes

      December 2, 2024

      Found on VirusTotal: The world’s first UEFI bootkit for Linux

      December 2, 2024

      Code found online exploits LogoFAIL to install Bootkitty Linux backdoor

      December 2, 2024

      Google and Kairos sign nuclear reactor deal with aim to power AI

      December 2, 2024
    • Science

      Spies hack Wi-Fi networks in far-off land to launch attack on target next door

      December 2, 2024

      QNAP firmware update leaves NAS owners locked out of their boxes

      December 2, 2024

      Found on VirusTotal: The world’s first UEFI bootkit for Linux

      December 2, 2024

      Code found online exploits LogoFAIL to install Bootkitty Linux backdoor

      December 2, 2024

      Google and Kairos sign nuclear reactor deal with aim to power AI

      December 2, 2024
    • Technology

      “Havard”-trained spa owner injected clients with bogus Botox, prosecutors say

      November 22, 2024

      The next Starship launch may occur in less than two weeks

      November 22, 2024

      For fame or a death wish? Kids’ TikTok challenge injuries stump psychiatrists

      November 22, 2024

      Nearly three years since launch, Webb is a hit among astronomers

      November 22, 2024

      Airborne microplastics aid in cloud formation

      November 22, 2024
    • Gaming

      Bazzite is the next best thing to SteamOS while we wait on Valve

      November 20, 2024

      Halls of Torment is Diablo cranked up to 50,000 kills/hour

      November 20, 2024

      GOG’s Preservation Program is the DRM-free store refocusing on the classics

      November 20, 2024

      How Valve made Half-Life 2 and set a new standard for future games

      November 20, 2024

      Dragon Age: The Veilguard and the choices you make while saving the world

      November 20, 2024
    • Gadgets

      Apple’s first Mac mini redesign in 14 years looks like a big aluminum Apple TV

      November 20, 2024

      GitHub Copilot moves beyond OpenAI models to support Claude 3.5, Gemini

      November 20, 2024

      Microsoft finally releases generic install ISOs for the Arm version of Windows

      November 20, 2024

      I, too, installed an open source garage door opener, and I’m loving it

      November 20, 2024

      Review: Amazon’s 2024 Kindle Paperwhite makes the best e-reader a little better

      November 20, 2024
    Technology News & TrendsTechnology News & Trends
    You are at:Home » Found: 280 Android apps that use OCR to steal cryptocurrency credentials
    Featured

    Found: 280 Android apps that use OCR to steal cryptocurrency credentials

    November 22, 2024Updated:November 22, 2024No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    An admin page showing OCR details.

    Credit:
    McAfee

    An admin page showing OCR details.

    Credit:

    McAfee

    “Upon examining the page, it became clear that a primary goal of the attackers was to obtain the mnemonic recovery phrases for cryptocurrency wallets,” Ryu wrote. “This suggests a major emphasis on gaining entry to and possibly depleting the crypto assets of victims.”

    Optical character recognition is the process of converting images of typed, handwritten, or printed text into machine-encoded text. OCR has existed for years and has grown increasingly common to transform characters captured in images into characters that can be read and manipulated by software.

    Ryu continued:

    This threat utilizes Python and Javascript on the server-side to process the stolen data. Specifically, images are converted to text using optical character recognition (OCR) techniques, which are then organized and managed through an administrative panel. This process suggests a high level of sophistication in handling and utilizing the stolen information.



    Python code for converting text shown in images to machine-readable text.

    Credit:
    McAfee

    Python code for converting text shown in images to machine-readable text.


    Credit:

    McAfee

    People who are concerned they may have installed one of the malicious apps should check the McAfee post for a list of associated websites and cryptographic hashes.

    The malware has received multiple updates over time. Whereas it once used HTTP to communicate with control servers, it now connects through WebSockets, a mechanism that’s harder for security software to parse. WebSockets have the added benefit of being a more versatile channel.



    A timeline of apps’ evolution.

    Credit:
    McAfee

    A timeline of apps’ evolution.


    Credit:

    McAfee

    Developers have also updated the apps to better obfuscate their malicious functionality. Obfuscation methods include encoding the strings inside the code so they’re not easily read by humans, the addition of irrelevant code, and the renaming of functions and variables, all of which confuse analysts and make detection harder. While the malware is mostly restricted to South Korea, it has recently begun to spread within the UK.

    “This development is significant as it shows that the threat actors are expanding their focus both demographically and geographically,” Ryu wrote. “The move into the UK points to a deliberate attempt by the attackers to broaden their operations, likely aiming at new user groups with localized versions of the malware.”

    Views: 203
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCracking the recipe for perfect plant-based eggs
    Next Article The key moment came 38 minutes after Starship roared off the launch pad

    Related Posts

    Biz & IT

    Spies hack Wi-Fi networks in far-off land to launch attack on target next door

    December 2, 2024
    Biz & IT

    QNAP firmware update leaves NAS owners locked out of their boxes

    December 2, 2024
    Biz & IT

    Found on VirusTotal: The world’s first UEFI bootkit for Linux

    December 2, 2024
    Add A Comment

    Comments are closed.

    Technical Analysis for AAPL by TradingView
    Demo
    Top Posts

    Spies hack Wi-Fi networks in far-off land to launch attack on target next door

    December 2, 2024

    QNAP firmware update leaves NAS owners locked out of their boxes

    December 2, 2024

    Found on VirusTotal: The world’s first UEFI bootkit for Linux

    December 2, 2024
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured Reviews

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured Reviews 2 Mins Read
    8.1
    Trends

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Trends 2 Mins Read
    8.9
    Featured Reviews

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Featured Reviews 6 Mins Read

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Spies hack Wi-Fi networks in far-off land to launch attack on target next door

    Tablet PC Market to Witness Exponential Growth by 2028, Sources Say

    Save $25 on Philips Wired Headphone For A Great Sounding Over-Ear Headphone

    Our Picks

    Spies hack Wi-Fi networks in far-off land to launch attack on target next door

    QNAP firmware update leaves NAS owners locked out of their boxes

    Found on VirusTotal: The world’s first UEFI bootkit for Linux

    Subscribe to Updates

    Stay updated with the latest breakthroughs in technology, innovation, and business trends from Faralogic.

    Technology News & Trends
    Facebook X (Twitter) Instagram Pinterest LinkedIn
    • User Agreement
    • Terms and Conditions
    • Disclaimer
    • About Us
    © 2025 FARALOGIC.

    Type above and press Enter to search. Press Esc to cancel.