Close Menu
CryptoDigestAlert.comCryptoDigestAlert.com
    What's Hot

    U.K. FCA Seeks Feedback on Consumer Duty for Crypto Companies

    January 25, 2026

    Best Crypto PR Agencies of 2025

    September 9, 2025

    Bitcoin prices stall – But THESE signals say BTC rally isn’t over!

    September 13, 2025
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Get In Touch
    Facebook X (Twitter) Instagram
    CryptoDigestAlert.comCryptoDigestAlert.com
    • News

      New trojan campaigns attack hundreds of crypto wallets and banking apps

      May 3, 2026

      Pi Network launches Protocol 23 on May 11

      May 1, 2026

      Bitcoin Reverses 3-Day Slide, Climbs Past $76K Despite $75M Long Liquidations

      April 30, 2026

      Pundit Shares The Most Important Thing To Remember About XRP

      April 29, 2026

      Aptos price prediction 2026, 2027, 2028-2031

      April 28, 2026
    • Technology

      Coinbase says crypto bill deal clears Senate path

      May 3, 2026

      Chainlink Market Shows Mixed Momentum at $9.20 as Whales Shift Millions of LINK

      May 2, 2026

      SBI adds Bitcoin, Ethereum and XRP rewards in Visa card push

      May 1, 2026

      Ondo Finance and Broadridge Unite to Bring Proxy Voting to Tokenized Stocks

      April 30, 2026

      Sam Bankman-Fried’s retrial request rejected by judge citing lack of new evidence

      April 29, 2026
    • Learn/Guide

      How to Optimize Company Operational Costs: A Manual on Modern Payment Ecosystems

      March 6, 2026

      6 Best Citizenship by Investment Programs for 2026

      February 23, 2026

      Best Smart Contract Auditors and Web3 Security Companies (2026): Ranked by Verifiable Public Evidence

      February 12, 2026

      Your Complete Guide to Smarter Investing

      January 29, 2026

      How to Use Cryptocurrency for Everyday Shopping in 2026

      January 23, 2026
    • Regulation

      Gemini Enters Prediction Market Race After CFTC License Approval

      April 30, 2026

      Senate Banking Panel Eyes Clarity Act Markup in May

      April 29, 2026

      Polymarket Seeks CFTC Nod to Restore U.S. Trading Access

      April 28, 2026

      New York AG Sues Coinbase, Gemini Over Prediction Markets

      April 24, 2026

      Thailand SEC Proposes New Rules to Expand Crypto Futures Access

      April 23, 2026
    • Live Pricing Chart
    CryptoDigestAlert.comCryptoDigestAlert.com
    Home»News»New trojan campaigns attack hundreds of crypto wallets and banking apps
    News

    New trojan campaigns attack hundreds of crypto wallets and banking apps

    May 3, 20264 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    New trojan campaigns attack hundreds of crypto wallets and banking apps.
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Cybersecurity researchers have found four active families of Android malware that are targeting +800 apps, including cryptocurrency wallets and banking apps. These malware use methods that most traditional security tools can’t detect.

    Zimperium’s zLabs team released results tracking the trojans known as RecruitRat, SaferRat, Astrinox, and Massiv.

    According to the company’s research, each family has its own command-and-control network that they use to steal login information, take over financial transactions, and get user data from infected devices.

    Crypto and banking apps face new threats from multiple malwares

    The malware families are a direct threat to anyone who manages crypto on Android.

    Once installed, the trojans can put fake login screens on top of real crypto and banking apps, stealing passwords and other private information in real time. The malware then puts a fake HTML page over the real app interface, making what the company called “a highly convincing, deceptive facade.”

    “Using Accessibility Services to monitor the foreground, the malware detects the exact moment a victim launches a financial application,” wrote security researchers from Zimperium.

    According to the report, the trojans can do more than just steal credentials. They can also capture one-time passcodes, stream a device’s screen to attackers, hide their own app icons, and stop people from uninstalling them.

    Each campaign uses a different bait to get people to fall for it.

    SaferRat spread itself by using fake websites that promised free access to premium streaming services. RecruitRat hid its payload as part of a job application process, sending targets to phishing sites that asked them to download a malicious APK file.

    Astrinox used the same kind of recruitment-based method, using the domain xhire[.]cc. Depending on the device used to visit that site, it showed different content.

    Android users were asked to download an APK, and iOS users saw a page that looked like the Apple App Store. However, security researchers found no proof that iOS was actually hacked.

    It was not possible to confirm how Massiv was distributed during the research cycle.

    All four trojans used phishing infrastructure, text-message scams, and social engineering that played on people’s need to act quickly or their curiosity to get them to sideload apps that were harmful.

    Crypto malware evades detection

    The campaigns aim to get around security tools.

    Researchers found that the malware families use advanced anti-analysis techniques and structural tampering with Android application packages (APKs) to keep what the company called “near-zero detection rates against traditional signature-based security mechanisms.”

    Network communications also mix in with regular traffic. The trojans use HTTPS and WebSocket connections to talk to their command servers. Some versions add extra layers of encryption on top of these connections.

    Another important thing is persistence. Modern Android banking trojans no longer use simple, one-stage infections. Instead, they use multi-stage installation processes that are meant to get around Android’s changing permission model, which has made it harder for apps to do things without the user’s explicit permission.

    The report did not identify particular crypto wallets or exchanges within the +800 targeted applications. But because of overlay attacks, passcode interception, and screen streaming, any Android-based crypto app could be at risk if a user installs a malicious APK from outside the Google Play Store.

    Downloading apps from links in text messages, job postings, or promotional websites is still one of the guaranteed ways for mobile malware to get into a smartphone.

    People who manage their crypto on Android devices should only use official app stores and be wary of pop-up messages that ask them to download something.

    Your bank is using your money. You’re getting the scraps. Watch our free video on becoming your own bank



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Pi Network launches Protocol 23 on May 11

    May 1, 2026

    Bitcoin Reverses 3-Day Slide, Climbs Past $76K Despite $75M Long Liquidations

    April 30, 2026

    Pundit Shares The Most Important Thing To Remember About XRP

    April 29, 2026

    Aptos price prediction 2026, 2027, 2028-2031

    April 28, 2026
    Top Posts

    How EU DAC8 Crypto Reporting Rule to Transform Exchange Compliance in 2026

    November 29, 2025

    BlackRock’s BUIDL tokenized MMF hits $100M in dividends

    December 30, 2025

    Kraken’s parent company Payward acquires crypto derivatives company Bitnomial

    April 17, 2026

    Welcome to CryptoDigestAlert.com! Your go-to source for fast, reliable updates from the ever-evolving world of cryptocurrency. Whether it's Bitcoin, altcoins, blockchain breakthroughs, or DeFi trends, we bring you timely insights, expert analysis, and key developments shaping the future of digital finance. Stay ahead with real-time crypto news and in-depth coverage.

    Top Insights

    New trojan campaigns attack hundreds of crypto wallets and banking apps

    May 3, 2026

    Pi Network launches Protocol 23 on May 11

    May 1, 2026

    Bitcoin Reverses 3-Day Slide, Climbs Past $76K Despite $75M Long Liquidations

    April 30, 2026
    Advertisement
    Demo
    • News
    • Technology
    • Learn/Guide
    • Regulation
    • Business
    • Live Pricing Chart
    © 2026. Burleys Holdings Ltd Company Reg: 15927118 - Unit 15 Manor Farm, Tarnock, Axbridge, UK, BS26 2SL - Design & SEO + GEO Developed By SEO - Craig Burley

    Type above and press Enter to search. Press Esc to cancel.