Hackers are selling counterfeit phones with crypto-stealing malware

Key Points

  • Cybersecurity firm Kaspersky has uncovered thousands of counterfeit Android smartphones sold online with preinstalled malware designed to steal crypto and other sensitive data.
  • The malware, a version of the Triada Trojan, gives attackers "almost unlimited control" over the device, allowing them to steal crypto by replacing wallet addresses.
  • The attackers have managed to transfer about $270,000 in various cryptocurrencies to their wallets, with the potential for more due to targeting untraceable cryptocurrencies like Monero.
  • The trojan can intercept texts, steal user account information, and even penetrate smartphone firmware before the device reaches the user.
  • Kaspersky researchers have confirmed 2,600 infections, with the majority in Russia, in the first three months of 2025.

Summary

Cybersecurity firm Kaspersky has revealed a significant threat involving counterfeit Android smartphones sold online at reduced prices, which come preloaded with the Triada Trojan malware. This malware grants attackers extensive control over the device, enabling them to steal cryptocurrencies by altering wallet addresses. According to Dmitry Kalinin from Kaspersky Labs, the attackers have already siphoned off approximately $270,000 in various cryptocurrencies, with the potential for more due to their targeting of untraceable cryptocurrencies like Monero. The malware not only steals crypto but also intercepts texts, including two-factor authentication codes, and can compromise user account information. The infection process starts even before the phones reach consumers, possibly due to a compromised supply chain. Kaspersky has confirmed 2,600 infections globally, with Russia being the most affected region in the first three months of 2025. The Triada Trojan, known since 2016, remains a formidable threat to Android users, particularly those involved in cryptocurrency transactions.

cointelegraph
April 3, 2025
Crypto
Read article

Related news