Attackers Broaden Victim Base to U.S. and European Users of Apps Like Bumble and Tinder and Acquire Ability to Remotely Manage Targets’ iPhones

OXFORD, U.K. — Ottobre 13, 2021 —

Sophos, a global leader in next-generation cybersecurity, has released new insight on an international cryptocurrency trading scam targeting iPhone users through popular dating apps, such as Bumble and Tinder. A report detailing the latest findings, “CryptoRom Fake iOS Cryptocurrency Apps Hit US, European Victims For At Least $1.4 Million,” shows that the operation has escalated. The attackers have expanded from targeting people in Asia to include people in the U.S. and Europe. Sophos has uncovered a Bitcoin wallet controlled by the attackers that contains nearly $1.4 million in cryptocurrency, allegedly collected from victims. Sophos researchers have code-named the threat “CryptoRom.”

“The CryptoRom scam relies heavily on social engineering at almost every stage,” said Jagadeesh Chandraiah, senior threat researcher at Sophos. “First, the attackers post convincing fake profiles on legitimate dating sites. Once they’ve made contact with a target, the attackers suggest continuing the conversation on a messaging platform. They then try to persuade the target to install and invest in a fake cryptocurrency trading app. At first, the returns look very good but if the victim asks for their money back or tries to access the funds, they are refused and the money is lost. Our research shows that the attackers are making millions of dollars with this scam.”

Double Trouble

In addition to stealing money, the attackers can also gain access to victims’ iPhones, according to Sophos’ research. In this version of the attack, cybercriminals leverage “Enterprise Signature,” a system for software developers that helps organizations to pre-test new iOS applications with selected iPhone users before they submit them to the official Apple App Store for review and approval.

With the functionality of the Enterprise Signature system, attackers can target larger groups of iPhone users with their fake crypto-trading apps and gain remote management control over their devices. This means the attackers could potentially do more than just steal cryptocurrency investments from victims. They could also, for instance, collect personal data, add and remove accounts, and install and manage apps for other malicious purposes.

“Until recently, the criminal operators mainly distributed the fake crypto apps through fake websites that resemble a trusted bank or the Apple App Store,” said Chandraiah. “The addition of the iOS enterprise developer system introduces further risk for victims because they could be handing the attackers the rights to their device and the ability to steal their personal data. To avoid falling victim to these types of scams, iPhone users should only install apps from Apple’s App Store. The golden rule is that if something seems risky or too good to be true – such as someone you barely know telling you about some ‘great’ online investment scheme that will deliver a big profit – then sadly, it probably is.”

Sophos recommends that users install a security solution on their mobile devices, such as Intercept X for Mobile, to protect iOS and Android devices from cyberthreats. It is also worth securing all home and personal computers with additional protection such as Sophos Home.

Further information on the fake cryptocurrency trading apps targeting iPhones as well as other mobile threats reported on by Sophos is available at SophosLabs Uncut.

Informazioni su Sophos

Sophos è un’azienda leader nell’ambito della cybersecurity e protegge 600.000 organizzazioni in tutto il mondo con una piattaforma basata sull’IA e servizi a cura di esperti. Sophos viene incontro alle esigenze delle organizzazioni, adattandosi al loro livello di maturità di sicurezza informatica e crescendo insieme ai clienti per tutelarli dai cyberattacchi. La sua soluzione offre la combinazione ottimale tra machine learning, automazione e dati di intelligence sulle minacce in tempo reale, aggiungendo le competenze umane degli esperti del team Sophos X-Ops, che lavorano in prima linea per garantire monitoraggio, rilevamento e risposta alle minacce 24/7.
Sophos offre un servizio di Managed Detection and Response (MDR) leader di settore, nonché una linea completa di tecnologie di sicurezza, tra cui soluzioni per la protezione di endpoint, rete, e-mail e cloud, nonché Extended Detection and Response (XDR), rilevamento delle minacce all’identità (Identity Threat Detection and Response, ITDR) e SIEM next-gen. Unite a servizi di consulenza a cura di esperti, queste funzionalità aiutano le organizzazioni a ridurre proattivamente il rischio e a rispondere in maniera più tempestiva, ottenendo il giusto livello di visibilità e scalabilità richiesto per tenersi un passo avanti rispetto a minacce in continua evoluzione.
La strategia go-to-market di Sophos si basa su un ecosistema di Partner che include Managed Service Provider (MSP), Managed Security Service Provider (MSSP), Rivenditori e Distributori, integrazioni per il marketplace, e Partner Cyber Risk; questa strategia offre alle organizzazioni la flessibilità di scegliere come stabilire rapporti di fiducia per la protezione della loro attività.  Sophos ha sede a Oxford, nel Regno Unito. Ulteriori informazioni sono disponibili su www.sophos.it.