By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Chinese Android Phones Shipped with Fake WhatsApp, Telegram Apps Targeting Crypto Users
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Chinese Android Phones Shipped with Fake WhatsApp, Telegram Apps Targeting Crypto Users
Computing

Chinese Android Phones Shipped with Fake WhatsApp, Telegram Apps Targeting Crypto Users

News Room
Last updated: 2025/04/16 at 4:28 AM
News Room Published 16 April 2025
Share
SHARE

Cheap Android smartphones manufactured by Chinese companies have been observed pre-installed with trojanized apps masquerading as WhatsApp and Telegram that contain cryptocurrency clipper functionality as part of a campaign since June 2024.

While using malware-laced apps to steal financial information is not a new phenomenon, the new findings from Russian antivirus vendor Doctor Web point to significant escalation where threat actors directly targeting the supply chain of various Chinese manufacturers to preload brand new devices with malicious apps.

“Fraudulent applications were detected directly in the software pre-installed on the phone,” the company said. “In this case, the malicious code was added to the WhatsApp messenger.”

Cybersecurity

A majority of the compromised devices are said to be low-end phones that mimic well-known premium models from Samsung and Huawei with names like S23 Ultra, S24 Ultra, Note 13 Pro, and P70 Ultra. At least four of the affected models are manufactured under the SHOWJI brand.

The attackers are said to have used an application to spoof the technical specification displayed on the About Device page, as well as hardware and software information utilities like AIDA64 and CPU-Z, giving users a false impression that the phones are running Android 14 and have improved hardware.

The malicious Android apps are created using an open-source project called LSPatch that allows the trojan, dubbed Shibai, to be injected into otherwise legitimate software. In total, about 40 different applications, like messengers and QR code scanners, are estimated to have been modified in this manner.

In the artifacts analyzed by Doctor Web, the application hijacks the app update process to retrieve an APK file from a server under the attacker’s control and searches for strings in chat conversations that match cryptocurrency wallet address patterns associated with Ethereum or Tron. If found, they are replaced with the adversary’s addresses to reroute transactions.

“In the case of an outgoing message, the compromised device displays the correct address of the victim’s own wallet, while the recipient of the message is shown the address of the fraudsters’ wallet,” Doctor Web said.

“And when an incoming message is received, the sender sees the address of their own wallet; meanwhile, on the victim’s device, the incoming address is replaced with the address of the hackers’ wallet.”

Besides changing the wallet addresses, the malware is also fitted with capabilities to harvest device information, all WhatsApp messages, and .jpg, .png, and .jpeg images from DCIM, Pictures, Alarms, Downloads, Documents, and Screenshots folders to the attacker’s server.

The intention behind this step is to scan the stored images for wallet recovery (aka mnemonic) phrases, allowing the threat actors to gain unauthorized access to victims’ wallets and drain the assets.

It’s not clear who is behind the campaign, although the attackers have been found to leverage about 30 domains to distribute the malicious applications and employ more than 60 command-and-control (C2) servers to manage the operation.

Cybersecurity

Further analysis of the nearly two dozen cryptocurrency wallets used by the threat actors has revealed that they have received more than $1.6 million over the last two years, indicating that the supply chain compromise has paid off in a big way.

The development comes as Swiss cybersecurity company PRODAFT uncovered a new Android malware family dubbed Gorilla that’s designed to collect sensitive information (e.g., device model, phone numbers, Android version, SIM card details, and installed apps), main persistent access to infected devices, and receive commands from a remote server.

“Written in Kotlin, it primarily focuses on SMS interception and persistent communication with its command-and-control (C2) server,” the company said in an analysis. “Unlike many advanced malware strains, Gorilla does not yet employ obfuscation techniques, indicating that it may still be under active development.”

In recent months, Android apps embedding the FakeApp trojan propagated via Google Play Store have also been found making use of a DNS server to retrieve a configuration that contains a URL to be loaded.

These apps, since removed from the marketplace, impersonate well-known and popular games and apps and come fitted with the ability to receive external commands that can perform various malicious actions like loading unwanted websites or serving phishing windows.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Amazon deal of the day: The Kindle Scribe is back down to its Big Spring Sale price
Next Article Researchers discover a organic treasure in a South African rock
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Soundcore P41i earbuds will stop your phone dying when you least want it to | Stuff
Gadget
This Blog Made Me Money While I Slept — Here’s How I Did It in 30 Minutes
Computing
Apple Maps still has a major flaw, and iOS 26 won’t fix it
News
Every fusion startup that has raised over $100M | News
News

You Might also Like

Computing

This Blog Made Me Money While I Slept — Here’s How I Did It in 30 Minutes

5 Min Read
Computing

The TechBeat: This Open Source Tool Could Save Your Data Team Hundreds of Hours (6/19/2025) | HackerNoon

5 Min Read
Computing

Windows 11 vs. Ubuntu Linux Performance On The AMD Ryzen AI Max PRO 390 “Strix Halo”

3 Min Read
Computing

NIO reportedly seeks external investors for chip business · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?