A sophisticated cybercriminal campaign targeting Indian investors through fraudulent stock and cryptocurrency schemes has escalated, with hackers leveraging social engineering, fake mobile applications, and compromised government websites to steal financial data. These attacks exploit the rapid growth of digital investment platforms, using Telegram channels, UPI payment systems, and fake trading apps to drain victims’ funds. The attackers operate by creating fake investment companies, impersonating legitimate entities like Binance and Tesla, and promoting unrealistic returns through Telegram groups such as “BITCOIN MONEY EARNING” (19,800+ subscribers) and “Wolf calls PAID Channel” (3,887 subscribers). As cryptocurrencies and digital trading gain traction in India, cybersecurity experts warn that such attacks will likely proliferate, necessitating coordinated efforts between regulators, platforms, and users to mitigate risks. Users attempting to access this tool are redirected to a spoofed WhatsApp group named “Elite Stock Trading Group,” which distributes APK files disguised as trading apps. Cybersecurity experts have uncovered a sophisticated multi-stage phishing campaign that exploits Gamma, an AI-powered presentation tool, to deliver credential-harvesting attacks targeting Microsoft account users. Cyfirma analysts noted a network of 15+ fraudulent Android applications, including stockheaven[.]site, which impersonate legitimate trading platforms. Users who enter UPI details or bank credentials have their data exfiltrated to a command-and-control server linked to Chinese operators, as evidenced by Mandarin comments in the APK’s source code. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The malware also employs persistence tactics by simulating legitimate app behavior, such as generating fake transaction histories and offering referral bonuses to encourage wider dissemination.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 16 Apr 2025 17:25:10 +0000