SEEDSNATCHER Android Malware Attacking Users to Exfiltrate Sensitive Data and Execute Malicious Commands
SeedSnatcher is a significant threat to cryptocurrency users, operating as sophisticated Android malware. Packaged under the name "Coin" and distributed via Telegram, it is designed to steal digital wallet recovery codes and execute remote commands on…
SeedSnatcher is a significant threat to cryptocurrency users, operating as sophisticated Android malware. Packaged under the name "Coin" and distributed via Telegram, it is designed to steal digital wallet recovery codes and execute remote commands on infected devices.
The malware, identified as com.pureabuladon.auxes, is part of a coordinated campaign with capabilities extending beyond simple data theft.
The attack employs deceptive distribution methods where promotional teams use unique agent identifiers to track installations and manage victims.
SeedSnatcher is particularly dangerous due to its multi-layered approach to evading security measures. Initially, it requests minimal permissions like SMS access, but once installed, it escalates its privileges to access sensitive information.
This gradual permission escalation reduces suspicion while establishing a persistent foothold on the device.
The malware's technical architecture demonstrates expertise in Android exploitation. It utilizes dynamic class loading, stealthy WebView content injection, and command-and-control instructions encoded as integers to hinder security detection systems.
Cyfirma security analysts identified that the malware maintains constant WebSocket communication with its command server, enabling real-time two-way communication for remote tasking.
The operators behind SeedSnatcher are believed to be China-based or Chinese-speaking, as the user interface is entirely in Chinese during demonstrations.
SeedSnatcher is a significant threat to cryptocurrency users, operating as sophisticated Android malware.
The presence of numerous compromised devices in their control panel suggests an active, operational ecosystem.
The operation is financially motivated, with a distributed campaign structure that includes commission systems routing money back to team leaders, indicating a professional criminal enterprise focused on cryptocurrency theft.
Wallet Interface Spoofing and Seed Phrase Harvesting
SeedSnatcher can create convincing fake cryptocurrency wallet interfaces to trick users into revealing their seed phrases.
The malware includes a mapping system that directs users to spoofed screens matching their preferred wallets, such as Trust Wallet, TokenPocket, imToken, MetaMask, Coinbase Wallet, TronLink, TronGlobal, Binance Chain Wallet, and OKX Wallet.
When a user opens a legitimate application, the malware's overlay permission allows it to display a counterfeit import screen resembling the genuine wallet interface.
For Trust Wallet, the malware hardcodes the legitimate package name com.wallet.crypto.trustapp and uses matching UI elements for maximum deception.
The code structure shows how the malware intercepts user input while maintaining the appearance of the genuine application.
The attack is effective due to BIP39 dictionary validation, ensuring only properly formatted mnemonic phrases are captured.
The malware loads the complete BIP39 wordlist from the application's assets, validating each word entry in real-time to ensure only valid phrases reach the attacker's server.
This mechanism increases the success rate of wallet takeovers, as attackers receive ready-to-import recovery codes with no failed attempts.
Once captured, these mnemonics are exfiltrated to the attacker's infrastructure, granting access to the victim's cryptocurrency holdings and enabling unauthorized fund transfers.
SeedSnatcher's orchestrated operation and ability to harvest active cryptocurrency wallets make it one of the most dangerous mobile malware threats targeting digital asset users today.
Based on reporting by Cyber Security News.
