Fake Apps Masked as Cryptocurrency, Trading, Banking Apps Duping iOS, Android Customers: Sophos

Counterfeit apps are impersonating major financial firms and popular cryptocurrency trading platforms, including Barclays, Gemini, Bitwala, Kraken, Binance, BitcoinHK, Bittrex, BitFlyer, and TDBank.

Advertisement
By Tasneem Akolawala | Updated: 14 May 2021 14:24 IST
Highlights
  • To bypass App Store, scammers exploit Apple’s a Super Signature process
  • Sophos found this issue while investigating fake app of Goldenway Group
  • Schemes to download these fake apps are leveraged through dating sites

Links to both iOS and Android platforms for these fake apps are made available

Photo Credit: Sophos

Several counterfeit versions of popular cryptocurrency trading, stock trading and banking apps have been discovered by Sophos on iOS and Android platforms, designed to steal sensitive information. All those who download these fake apps can be potential victims of data theft. Counterfeit apps are impersonating major financial firms and popular cryptocurrency trading platforms, including Barclays, Gemini, Bitwala, Kraken, Binance, BitcoinHK, Bittrex, BitFlyer, and TDBank. Sophos found these fake apps while looking into a fraudulent mobile trading app that masqueraded as one tied to a well-known Asia-based trading company, Goldenway Group.

Sophos says that schemes to distribute these fake apps are leveraged though dating sites and social media. These apps are made cleverly to look like those belonging to the actual legitimate ones. “These websites forwarded victims to third-party sites that delivered iOS mobile applications via configuration management schemes, iOS mobile device management payloads carrying “Web Clips”, or Android apps depending on the device used, the report by Sophos notes.

The report details one victim's misery wherein he touched base with the scammers through social media and a dating site. The scammers befriended the victim and shifted communications to a messaging app. They avoid requests for face-to-face meetings, citing the COVID-19 pandemic. After gaining trust, they then convinced the victim to download a cryptocurrency trading app, sending the victim a link. They even walked the victim through the installation process and encouraged him to buy cryptocurrency and transfer it into their wallet. After the transfer was made, the scammers blocked the victim's account and ended communication.

Advertisement

The fake app that the victim was tricked to download was an impersonation of the Hong Kong-based trading and investment company called Goldenway Group. The company is aware of this scam and even has posted a warning on the company's actual website with an alert about fraudsters scamming users with a similar named site and asks its users to steer clear of such apps.

Advertisement

To bypass the App Store, scammers use third-party services to deploy what's known as a Super Signature process. This allows app developers to use Apple's ad-hoc application distribution method to deliver applications to iOS devices—a process intended to allow developers to distribute apps directly to a limited number of devices for testing. However, it is being abused by malicious pp developers. Scammers even used the Web Clips technique to dupe iPhone customers.

To avoid falling prey to such malicious apps, practice the following guidelines.

  1. Users should only install apps from trusted sources such as Google Play and Apple's App Store.
  2. Developers of popular apps often have a website, which directs the users to the genuine app.
  3. Users should verify if the app was developed by its genuine developer.
  4. Install an antivirus app on your mobile device.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Hogwarts Legacy Tops 40 Million Copies Sold
  3. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  4. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  5. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  6. Infinix Xpad Edge With 13.2-Inch Display, 8,000mAh Battery Launched
  7. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  8. Google's Pixel Phones Get a Second December Update With These Fixes
  9. Here Are Some Lesser-Known WhatsApp Features You Might Not Know Exist
  10. OpenAI Is Now Reviewing Third-Party Apps to Add Them to ChatGPT
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.