The News Chronicle
  • About Us
  • Advert Rates
  • Contact Us
  • Privacy Policy
Thursday, March 23, 2023
Advertisement
ADVERTISEMENT
  • News
    • Breaking
    • Business
    • Celebs
    • Sports
    • Africa
    • Technology
    • World News
  • Social Diary
    • Events
  • Columns
    • Monday
    • Tuesday
    • Wednesday
    • Thursday
    • Friday
    • Sunday
    • Opinions
    • Editorial: Our Stand
  • TNC TV
  • Interviews
  • Books
    • Reviews
    • Author Profiles
  • Entertainment
  • Gossip
No Result
View All Result
  • News
    • Breaking
    • Business
    • Celebs
    • Sports
    • Africa
    • Technology
    • World News
  • Social Diary
    • Events
  • Columns
    • Monday
    • Tuesday
    • Wednesday
    • Thursday
    • Friday
    • Sunday
    • Opinions
    • Editorial: Our Stand
  • TNC TV
  • Interviews
  • Books
    • Reviews
    • Author Profiles
  • Entertainment
  • Gossip
No Result
View All Result
The News Chronicle
No Result
View All Result
  • News
  • Social Diary
  • Columns
  • TNC TV
  • Interviews
  • Books
  • Entertainment

Path Naija News » News » Apple store is a source of bogus software, according to Sophos

Apple store

Apple store is a source of bogus software, according to Sophos

Ken Ibenne by Ken Ibenne
2 months ago
in News, World News
Reading Time: 2 mins read
A A
0
ADVERTISEMENT
Share on FacebookShare on TwitterShare on Whatsapp

The cybersecurity company Sophos has published new research on the sophisticated financial fraud schemes known as CryptoRom scams, which take advantage of and dupe users of dating apps into making fictitious cryptocurrency investments.

The first bogus CryptoRom apps, Ace Pro and MBM BitScan, allegedly managed to get past Apple’s stringent security measures, according to Sophos’ most recent research, “Fraudulent Trading Apps Sneak into Apple and Google App Stores.”

RelatedPosts

FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

March 22, 2023
Soludo Vows Aggressive Road Construction In Anambra, Flags Off 9 Roads, 2 Bridges

Abandoning Projects: Soludo Dismisses Allegations In Viral Video

March 22, 2023
…As Fire Guts Onitsha Main Market, Soludo Commiserates with Traders

…As Fire Guts Onitsha Main Market, Soludo Commiserates with Traders

March 22, 2023

It claims that in the past, fraudsters persuaded users to download unauthorized iPhone apps that were not authorized by the Apple App Store using workaround approaches.

According to Sophos, both Apple and Google were instantly contacted about the phony apps and both companies have now taken them down from their respective stores.

Jagadeesh Chandraiah, Senior Threat Researcher, Sophos, said: “In general, it’s hard to get malware past the security review process in the Apple App Store. That’s why, when we originally began investigating CryptoRom scams targeting iOS users, the scammers would have to persuade users to first install a configuration profile before they could install the fake trading app.”

“This obviously involves an additional level of social engineering—a level that’s hard to surmount. Many potential victims would be ‘alerted’ that something wasn’t right when they couldn’t directly download a supposedly legitimate app. By getting an application onto the App Store, the scammers have vastly increased their potential victim pool, particularly, since most users inherently trust Apple.”

Chandraiah added: “Both apps are also not affected by iOS’ new Lockdown mode, which prevents scammers from loading mobile profiles helpful for social engineering. In fact, these CryptoRom scammers may be shifting their tactics—i.e., focusing on bypassing the App Store review process—in light of the security features in Lockdown.”

He explained that the con artists constructed and actively maintained a bogus Facebook profile and persona of a woman who was purportedly leading a luxurious lifestyle in London in order to entice the victim, who was duped by Ace Pro, for example.

“After building a rapport with the victim, the scammers suggested the victim download the fraudulent Ace Pro app and the cryptocurrency fraud unfolded from there.

“Ace Pro is described in the app store as a QR code scanner but is a fraudulent crypto trading platform. Once opened, users see a trading interface where they can supposedly deposit and withdraw currency. However, any money deposited goes directly to the scammers,” he contuned.

Sophos thinks the scammers made the program connect to a remote website when it was first submitted for review in order to get past the App Store security.

Advertisement. Scroll to continue reading.

To provide the domain a credible appearance to app reviewers, the domain also contained QR scanning code. However, after the app was accepted, the fraudsters changed its URL to point to a site registered in Asia. This domain makes a request, to which another server responds with content, ultimately delivering the phony trading interface.

MBM BitScan is also available as an Android app, although it is listed on Google Play under the name BitScan, claims Sophos.

According to the research, two apps connect with the same Command and Control (C2) infrastructure, which then does so with a server that appears to be a server for a real Japanese crypto company.

Because everything else is done through a web interface, it is challenging for Google Play’s code reviewers to identify it as fraudulent.

Tags: Apple store
Plugin Install : Subscribe Push Notification need OneSignal plugin to be installed.
Previous Post

Sustainable Energy Fund for Africa grant to drive electric mobility shift in seven African countries

Next Post

Sinoma and Dangote have agreed to build a new 6MMT cement mill in Ogun

Ken Ibenne

Ken Ibenne

Related Posts

FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

March 22, 2023
Soludo Vows Aggressive Road Construction In Anambra, Flags Off 9 Roads, 2 Bridges

Abandoning Projects: Soludo Dismisses Allegations In Viral Video

March 22, 2023
…As Fire Guts Onitsha Main Market, Soludo Commiserates with Traders

…As Fire Guts Onitsha Main Market, Soludo Commiserates with Traders

March 22, 2023
Anambra Govt Partners Microsoft, Wootlab, to Train 20,000 Youths

Anambra Govt Partners Microsoft, Wootlab, to Train 20,000 Youths

March 22, 2023
Atiku Joins Peter Obi, Petition INEC, Tibunu and APC

Atiku Joins Peter Obi, Petition INEC, Tibunu and APC

March 22, 2023
US to Impose Visa Ban on Electoral Offenders in Lagos, Kano and Others

US to Impose Visa Ban on Electoral Offenders in Lagos, Kano and Others

March 22, 2023
Next Post
cement mill

Sinoma and Dangote have agreed to build a new 6MMT cement mill in Ogun

ADVERTISEMENT

What's New?

Buhari Should Release Kanu Based on UN’s Directive
Opinions

The Vindication of Mazi Nnamdi Kanu and the Biafra Question

by Peter Omonua
March 22, 2023
0

Someone forwarded an audio recording to me few days ago which must have been preserved for more than 57 years....

Read more
FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

FACT CHECK: Did South African Politician and Activist, Julius Malema Call for the Disintegration of Nigeria Over 2023 Polls?

March 22, 2023
Soludo Vows Aggressive Road Construction In Anambra, Flags Off 9 Roads, 2 Bridges

Abandoning Projects: Soludo Dismisses Allegations In Viral Video

March 22, 2023
Prev Next
ADVERTISEMENT
ADVERTISEMENT
  • © 2022 The News Chronicle