Home -
Original -
Main body -

WikiFX Express

Exness
TMGM
EC markets
XM
FXTM
FOREX.com
GTCFX
AVATRADE
IC Markets Global
D prime

New trojan campaigns attack hundreds of crypto wallets and banking apps

WikiFX
| 2026-05-04 11:14

Abstract:Four Android malware families are targeting over 800 crypto and banking apps, using fake login screens, OTP interception, and stealth techniques to steal sensitive data while evading traditional security tools.

WhatsApp Image 2026-05-04 at 11.11.45 AM.jpeg

Cybersecurity researchers have identified four active families of Android malware that are currently targeting more than 800 applications, including cryptocurrency wallets and banking platforms. These malware strains, known as RecruitRat, SaferRat, Astrinox and Massiv, are designed to evade traditional security systems, posing a significant risk to users who manage financial assets on mobile devices. The findings were released by Zimperiums zLabs team, which has been tracking these threats and their evolving capabilities.

Each malware family operates through its own command-and-control infrastructure, enabling attackers to steal login credentials, intercept financial transactions and extract sensitive user data from infected devices. Once installed, the malware can overlay fake login screens on top of legitimate applications, capturing passwords and private information in real time. Researchers noted that these malicious interfaces are highly convincing, often using deceptive HTML overlays that closely mimic genuine app environments. By leveraging Androids Accessibility Services, the malware can detect when a user opens a financial application and immediately trigger the attack.

Beyond credential theft, these trojans have advanced capabilities that further increase their impact. They can intercept one-time passcodes, stream a device‘s screen to remote attackers, conceal their own presence by hiding app icons and prevent users from uninstalling them. The distribution methods vary across campaigns, with each malware family using different tactics to lure victims. SaferRat has been spread through fake websites offering free access to premium streaming services, while RecruitRat has been embedded in fraudulent job application processes that direct users to download malicious APK files. Astrinox has used similar recruitment-based tactics through domains such as xhire[.]cc, delivering different content depending on the user’s device. Although iOS users may encounter pages that resemble the Apple App Store, there is currently no evidence of successful iOS compromise. The distribution method for Massiv remains unclear, but all four families rely heavily on phishing techniques, text message campaigns and social engineering strategies that exploit urgency and curiosity.

One of the most concerning aspects of these malware campaigns is their ability to bypass detection. Researchers found that they employ advanced anti-analysis techniques and manipulate Android application package structures to achieve near-zero detection rates against traditional signature-based security tools. Their network communications are also designed to blend in with normal traffic, using encrypted HTTPS and WebSocket connections, sometimes with additional layers of encryption. Furthermore, these threats use multi-stage installation processes to circumvent Androids evolving permission controls, allowing them to maintain persistence on infected devices.

Although the report does not specify which cryptocurrency wallets or exchanges are directly targeted, the nature of overlay attacks, passcode interception and screen monitoring means that any Android-based financial application could be vulnerable if users install software from untrusted sources. The primary risk arises when users download applications from links received through text messages, job postings or promotional websites, rather than from official app stores.

As mobile-based financial activity continues to grow, this development highlights the importance of maintaining strict security practices. Users managing cryptocurrency or banking activities on Android devices are strongly advised to download applications only from verified platforms and remain cautious of unsolicited prompts to install software. Vigilance in app sourcing and awareness of emerging threats remain essential in protecting digital assets in an increasingly complex cybersecurity landscape.

20251209-161539.jpeg
20260126-101313.png
CryptocurrencyCrypto Market Crypto Markets#CryptoNews

Read more

Robert Dunlap Sentenced To 23 Years For Meta 1 Coin Crypto Scam

Robert Dunlap was sentenced to 23 years in prison for a $20 million Meta-1 Coin crypto fraud that misled around 1,000 investors with false claims of asset backing, guaranteed returns, and fake profitability.

Original 2026-05-04 11:01

IVISION Exposure Report: Poor Withdrawals & Account Freeze Instances

IVISION, a Saint Lucia-based trading firm, mostly receives negative reviews from users. They claim that the broker’s withdrawal process is a scam, a deliberate attempt to defraud investors. At the same time, some traders have complained of an account freeze by the brokerage entity upon withdrawals. We have investigated user complaints in this IVISION review article. Keep reading.

Original 2026-04-27 22:55

Blueberry Markets Review: Examining the Latest User Complaints in 2026

Blueberry Markets, an Australia-based brokerage entity, is receiving a lot of complaints from users amid alleged trading scams in 2026. Complaints range from withdrawal denials to unexplained account blocks and profit deductions. These complaints have made their way to numerous broker review platforms such as WikiFX. This article thus aims to provide a comprehensive insight into recent user experiences with the broker. Read on as we share Blueberry Markets review containing user complaints and a statement from the WikiFX team on overall aspects, including its regulatory status. Let’s start investigating!

Original 2026-04-25 19:56

Coinbase Announces USDC-INR Trading Services for Indian Users

Paving the way for smoother crypto-to-fiat transactions, Coinbase has officially launched the USDC-INR trading services for Indian users. According to the official release, there will be a phased rollout of this service to other Coinbase products, including Coinbase.com, the mobile app and Coinbase Advanced platforms, soon. Indian users having been verified by the cryptocurrency exchange will be able to use this trading pair. The launch is aimed at ensuring an institutional solution for P2P users in India.

Original 2026-04-23 23:13

WikiFX Express

Exness
TMGM
EC markets
XM
FXTM
FOREX.com
GTCFX
AVATRADE
IC Markets Global
D prime

WikiFX Broker

FXTM

FXTM

Regulated
ATFX

ATFX

Regulated
XM

XM

Regulated
FXCM

FXCM

Regulated
FOREX.com

FOREX.com

Regulated
DLSM

DLSM

Regulated
FXTM

FXTM

Regulated
ATFX

ATFX

Regulated
XM

XM

Regulated
FXCM

FXCM

Regulated
FOREX.com

FOREX.com

Regulated
DLSM

DLSM

Regulated

WikiFX Broker

FXTM

FXTM

Regulated
ATFX

ATFX

Regulated
XM

XM

Regulated
FXCM

FXCM

Regulated
FOREX.com

FOREX.com

Regulated
DLSM

DLSM

Regulated
FXTM

FXTM

Regulated
ATFX

ATFX

Regulated
XM

XM

Regulated
FXCM

FXCM

Regulated
FOREX.com

FOREX.com

Regulated
DLSM

DLSM

Regulated

Latest News

Why Small Position Sizes and Less Trading Keep You Alive

WikiFX
2026-05-04 12:30

Decoding Currency Pairs and Finding the Right Broker Account

WikiFX
2026-05-04 12:30

Yen Stabilizes While Gold Prices Slip

WikiFX
2026-05-04 12:30

State Street Group Review 2026: Ponzi Scheme Warnings, Unverified Regulation, and Extreme Risk

WikiFX
2026-05-04 13:00

FCA-Regulated Forex Brokers Are Declining — 31 Platforms to Avoid

WikiFX
2026-05-04 11:59

FXORO Review: The Dark Side of a Market Maker Exposed

WikiFX
2026-05-04 12:30

GWFX Review 2026: Platform Outages, Missing Funds, and Unverified Regulation

WikiFX
2026-05-04 12:30

GameStop makes $55.5bn takeover offer for eBay

WikiFX
2026-05-04 00:18

Collapsed CFD Broker Director Pleads Guilty to Misusing $490K Client Funds

WikiFX
2026-05-04 11:49

New trojan campaigns attack hundreds of crypto wallets and banking apps

WikiFX
2026-05-04 11:14

Rate Calc

USD
CNY
Current Rate: 0

Amount

USD

Available

CNY
Calculate

You may also like

Nexglobmarket

Nexglobmarket

VEXITH Capital

VEXITH Capital

POLESTAR MARKETS

POLESTAR MARKETS

TRADE BAZAAR

TRADE BAZAAR

WwTradelink

WwTradelink

WONDERFX

WONDERFX

GXGLOBAL MINING

GXGLOBAL MINING

GLOBEX ULTRA

GLOBEX ULTRA

APOLLO

APOLLO

LLA

LLA