Cybersecurity Researchers Find 20 Crypto-Phishing Apps on Google Play Store: Check List

These apps impersonate legitimate crypto wallets on the Play Store, say researchers.

Advertisement
Written by Shaurya Tomer, Edited by Siddharth Suvarna | Updated: 9 June 2025 14:11 IST
Highlights
  • The crypto-phishing apps are said to mimic legit wallets like Hyperliquid
  • Users were tricked into entering their 12-word mnemonic phrases
  • The report links over 50 phishing domains to the discovered apps

Most of the crypto-phishing apps have been removed from the Google Play Store

Photo Credit: Pixabay/ Sergei Tokmakov

A team of cybersecurity researchers have found 20 apps on the Google Play Store which were targeting cryptocurrency wallet users. According to a report by a cybersecurity research firm, these crypto-phishing applications impersonated legitimate crypto wallets such as Hyperliquid, PancakeSwap, and Raydium. Threat actors leveraged phishing tactics and compromised or repurposed developer accounts, forcing users to enter their 12-word mnemonic phrase on a web-based false wallet interface and gaining access to their real wallets, the report stated.

Crypto-Phishing Apps on Google Play Store

Cybersecurity researchers at Cyble Research and Intelligence Labs (CRIL) have identified over 20 cryptocurrency phishing apps on the Google Play Store. The apps reportedly used similar package names and descriptions as legitimate crypto wallet apps but were published under different developer accounts which are often compromised. Alternatively, the report mentions some of these apps were also listed under repurposed developer accounts which were originally used for distribution of apps related to gaming, live streaming, and video download.

The malicious apps discovered on the Play Store also embedded Command and Control (C&C) URLs within their privacy policies to appear as legitimate. Threat actors were said to use the Median framework to convert web pages into Android apps.

Advertisement

Once an app is installed and opened by the victim, a URL, which resembles the privacy policy, redirects them to a phishing website. It is reported to have been designed to specifically steal 12-word mnemonic phrases via a WebView in the app. This results in the threat actor gaining access to the victim's crypto wallet and potentially draining all of the funds.

Advertisement

The report states these apps were linked to a network of over 50 phishing domains. Cybersecurity researchers found the following apps with their respective package names and privacy policy URLs on the Google Play Store:

Name Package Name Privacy Policy
Pancake Swap co.median.android.pkmxaj hxxps://pancakedentfloyd.cz/privatepolicy.html
Suiet Wallet co.median.android.ljqjry hxxps://suietsiz.cz/privatepolicy.html
Hyperliquid co.median.android.jroylx hxxps://hyperliqw.sbs/privatepolicy.html
Raydium co.median.android.yakmje hxxps://raydifloyd.cz/privatepolicy.html
Hyperliquid co.median.android.aaxbjp hxxps://hyperliqw.sbs/privatepolicy.html
Bulix Crypto co.median.android.ozjwka hxxps://bullxni.sbs/privatepolicy.html
OpenOcean Exchange co.median.android.ozjljk hxxps://openoceansi.sbs/privatepolicy.html
Suiet Wallet co.median.android.mpeaaw hxxps://suietsiz.cz/privatepolicy.html
Meteora Exchange co.median.android.kbxqaj hxxps://meteoraflordoverdose.sbs/privatepolicy.html
Raydium co.median.android.epwzyq hxxps://raydifloyd.cz/privatepolicy.html
SushiSwap co.median.android.pkezyz hxxps://sushijames.sbs/privatepolicy.html
Raydium co.median.android.pkzyjr hxxps://raydifloyd.cz/privatepolicy.html
SushiSwap co.median.android.briljb hxxps://sushijames.sbs/privatepolicy.html
Hyperliquid co.median.android.djerqq hxxps://hyperliqw.sbs/privatepolicy.html
Suiet Wallet co.median.android.epeall hxxps://suietwz.sbs/privatepolicy.html
Bulix Crypto co.median.android.braqdy hxxps://bullxni.sbs/privatepolicy.html
Harvest Finance blog co.median.android.ljmeob hxxps://harvestfin.sbs/privatepolicy.html
Pancake Swap co.median.android.djrdyk hxxps://pancakedentfloyd.cz/privatepolicy.html
Hyperliquid co.median.android.epbdbn hxxps://hyperliqw.sbs/privatepolicy.html
Suiet Wallet co.median.android.noxmdz hxxps://suietwz.sbs/privatepolicy.html

"These apps have been progressively discovered over recent weeks, reflecting an ongoing and active campaign", researchers said. They promptly reported them to Google, leading to their removal from the Play Store. Users are advised to take immediate action and uninstall them from their devices, in addition to securing their crypto wallet.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Series Launch: Here's a Quick Look at Everything Leaked So Far
  2. Xiaomi 15T Series Will Launch With Leica-Tuned Cameras on This Date
  3. Moto Pad 60 Neo India Launch Date, Key Features, Availability Confirmed
  4. iPhone 17 Apple's Event: Everything You Need to Know About the New iPhone
  5. 5 Biggest iPhone 17 Pro Leaks Ahead of Apple's 'Awe Dropping' Event
  6. Oppo F31 Series to Launch in India on September 15: All You Need to Know
  7. Coolie OTT Release Date is Confirmed: All You Need to Know
  8. iPhone 17 Air, Apple's Slimmest Phone: What to Expect
  9. These Poco Phones Will Be Discounted During the Flipkart Big Billion Days
  1. Diamond 'Super-Earth' May Not Be Quite as Precious as Once Thought, Study Finds
  2. NASA's James Webb Space Telescope Captures Lobster Nebula’s Towering Spires and Massive Stars
  3. Could a Planet Exist Without a Host Star? Astronomers Say Rogue Worlds May Roam Freely
  4. Exoplanets Explained: How Astronomers Find Worlds Orbiting Stars Beyond the Sun
  5. sPHENIX Detector Clears Test to Study Quark-Gluon Plasma Which Formed After the Big Bang, Claims Study
  6. UY Scuti Reigns as the Universe’s Biggest Known Star, but Its Crown May Be at Risk
  7. Legion Legion Go 2 Will Get ROG Xbox Ally's New Full-Screen Xbox Interface Next Year
  8. Google Nest Cam Outdoor and Indoor Models, Nest Doorbell With Gemini AI Spotted in a Retail Store
  9. Param Sundari OTT Release: When and Where to Watch Janhvi Kapoor-Starrer Online?
  10. Bitcoin’s Largest Whale Dump Since 2022: A Cause for Concern or Just Market Noise?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.