cryptonews
2025-07-31 08:15:57

10 Million People Globally Targeted by Fake Crypto App Ads, Check Point Warns

A global malware campaign has exposed more than 10 million people to deceptive crypto app ads, according to a new report from cybersecurity firm Check Point . Key Takeaways: Fake crypto app ads have exposed over 10 million people to malware. The malware uses JavaScript and advanced evasion tactics to avoid detection. Victims risk losing passwords, Telegram data, and access to crypto wallets. The campaign, which mimics nearly 50 popular crypto applications such as Binance, MetaMask, and Kraken, has been operating under the radar since at least March 2024. Dubbed “JSCEAL” by Check Point Research, the operation deploys fake crypto app interfaces through online advertisements, luring users into downloading malware that siphons sensitive data. Stealthy JavaScript Malware Evades Detection with Advanced Tactics The malicious software leverages JavaScript and employs advanced evasion techniques, making it difficult to detect and analyze. Check Point highlighted the role of social media platforms in enabling the campaign’s scale. Meta’s ad tools showed over 35,000 malicious advertisements were disseminated in just the first half of 2025. While an estimated 3.5 million users in the European Union encountered these ads, Check Point noted the campaign also targeted users in Asia — regions where crypto trading and social media usage are particularly dense. The firm stressed that estimating the precise number of infected devices remains difficult, given that ad impressions do not directly translate into malware infections. Nonetheless, the campaign’s sophistication and broad targeting suggest the real impact could be much higher than initial estimates. The malware tricks victims by presenting a website that closely resembles the real app’s homepage. When users attempt to install what appears to be a legitimate application, a hidden malware installation runs in parallel. The app often opens the actual platform’s interface to avoid suspicion, while stealing data in the background. Thousands tricked by fake crypto apps via Facebook ads. They install a stealthy new malware—JSCEAL—that hijacks wallets, steals passwords in real-time, and evades most detection tools. Worse? It's still active. Here’s how it works (and how to avoid it) ↓… pic.twitter.com/BnpsGI5RLZ — The Hacker News (@TheHackersNews) July 30, 2025 Once installed, the malware collects a wide range of personal information. This includes keystrokes, which can expose passwords, Telegram credentials, browser cookies, and even saved autofill data. It also has the capability to manipulate crypto browser extensions like MetaMask, making it a significant threat to digital asset holders. Check Point emphasized that the malware’s design relies heavily on obfuscation and compiled code, further complicating analysis. The goal appears to be the extraction of as much device and user data as possible, sending it to threat actors likely seeking to monetize the information or breach users’ crypto wallets. Study Reveals Widespread Leaks of Crypto Keys A recent study has revealed the extent of sensitive information leaked through ransomware attacks and data breaches, including key financial documents and crypto keys. The report, which analyzed over 141 million records from 1,297 breach incidents, revealed that cryptographic keys were stolen in 18% of the breaches. Financial documents appeared in 93% of the breach incidents studied, accounting for 41% of all analyzed files. Nearly half included bank statements, and over a third contained International Bank Account Numbers. In 82% of the cases, customer or corporate personally identifiable information (PII) was exposed, much of it originating from customer service interactions. The post 10 Million People Globally Targeted by Fake Crypto App Ads, Check Point Warns appeared first on Cryptonews .

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.