Crypto trading scam targets iPhone users looking for love
Researchers at Sophos have uncovered a cryptocurrency trading scam that targets iPhone users through popular dating apps, such as Bumble and Tinder.
Researchers have code-named the threat 'CryptoRom' and have discovered a Bitcoin wallet controlled by the attackers that contains nearly $1.4 million in cryptocurrency, allegedly collected from victims.
"The CryptoRom scam relies heavily on social engineering at almost every stage," says Jagadeesh Chandraiah, senior threat researcher at Sophos. "First, the attackers post convincing fake profiles on legitimate dating sites. Once they've made contact with a target, the attackers suggest continuing the conversation on a messaging platform. They then try to persuade the target to install and invest in a fake cryptocurrency trading app. At first, the returns look very good but if the victim asks for their money back or tries to access the funds, they are refused and the money is lost. Our research shows that the attackers are making millions of dollars with this scam."
In addition to stealing money, the attackers can also gain access to victims' iPhones, according to the research. In this version of the attack, cybercriminals use 'Enterprise Signature,' a system for software developers that helps organizations to pre-test new iOS applications with selected iPhone users before they submit them to the official Apple App Store for review and approval.
Using the functionality of the Enterprise Signature system attackers can target larger groups of iPhone users with their fake crypto-trading apps and gain remote management control over their devices.
"Until recently, the criminal operators mainly distributed the fake crypto apps through fake websites that resemble a trusted bank or the Apple App Store," adds Chandraiah. "The addition of the iOS enterprise developer system introduces further risk for victims because they could be handing the attackers the rights to their device and the ability to steal their personal data. To avoid falling victim to these types of scams, iPhone users should only install apps from Apple's App Store. The golden rule is that if something seems risky or too good to be true -- such as someone you barely know telling you about some 'great' online investment scheme that will deliver a big profit -- then sadly, it probably is."
You can read more about the scam, along with tips on how to protect yourself, on the Sophos site.
Image credit: jesterpop / Shutterstock