Security News > 2021 > August > Bogus Cryptomining Apps Infest Google Play

Bogus Cryptomining Apps Infest Google Play
2021-08-18 18:26

Google has removed eight deceptive mobile apps from the Play Store that masquerade as cryptocurrency cloud-mining applications but which really exist to lure users into expensive subscription services and other fraudulent activity.

Two of the apps added insult to injury by requiring users to purchase them, researchers found: Crypto Holic - Bitcoin Cloud Mining costs $12.99 to download, while Daily Bitcoin Rewards - Cloud Based Mining System cost $5.99.

Trend Micro's analysis showed that no actual mining activity was carried out by the apps - rather, "Fake mining activity on the apps' user interface is carried out via a local mining simulation module that includes a counter and some random functions."

The apps persist in their ruse, prompting users to pay in-app for supposedly increased cryptocurrency-mining capabilities - a "Service" that ranges from $14.99 to as high as $189.99.

"The app called Daily Bitcoin Rewards - Cloud Based Mining System prompts its users to upgrade their cryptomining capacity by 'buying' their favorite mining machines to earn more coins at a faster rate," Fang noted.

Fake apps will receive numerous 5-star reviews - pay more attention to 1-star reviews.


News URL

https://threatpost.com/bogus-cryptomining-apps-google-play/168785/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 994 4851 2756 1634 10235