In the evolving landscape of Web3, cybersecurity firm SlowMist has uncovered a new phishing attack targeting cryptocurrency users. The crypto victim in this case fell prey to a fake Skype application downloaded from the internet. It resulted in the theft of their crypto funds. SlowMist’s Security Team revealed that the same group behind a previous fake Binance app was responsible for this latest incident.
Fake Apps Targeting Social Media Apps Like Skype for Crypto
Phishing incidents involving fake applications are becoming increasingly common in the Web3 space. Users, especially in regions where Google Play is inaccessible, often resort to downloading apps directly from the internet. However, wallets and exchanges are typical targets. It includes social media applications like Telegram, WhatsApp, and Skype are also under constant threat.
The victim, who reached out to SlowMist’s Security Team, reported the loss of funds after using a Skype app downloaded from the internet. The team started an analysis based on the provided fake Skype phishing sample.
The fake app’s signature information appeared simple and nearly empty. Both the owner and publisher are labeled as ‘CN,’ suggesting a potential Chinese origin. The certificate’s effective date of September 11, 2023, indicated the app’s recent creation. Further investigation revealed that the fake app used an outdated version (8.87.0.403). It is compared to the latest official Skype version (8.107.0.215).

Source: Slowmist
SlowMist Decodes Malicious Operations in Fake Skype APK
Baidu search results revealed multiple sources of the same fake Skype version. It confirms its widespread distribution with reliable signature information. Analysis of the APK (Android Application Package) showed signs of interference. It also indicates the injection of malicious code.
Trending Now: Bithumb Eyes Nasdaq IPO in 2025 to Challenge Upbit Dominance
The fake app utilized the Bangcle protection to encapsulate the APK, a common defence tactic against analysis. SlowMist’s Security Team found that the fake app primarily manipulated the widely used Android network framework. As okhttp3 processes all Android traffic requests, it becomes an essential target for phishing attacks.
Through the Weibu asset mapping platform, SlowMist identified the phishing backend domain ‘bn-download3.com. It imitates Binance on November 23, 2022. The discovery emphasizes the continuous need for user awareness. It also highlights the importance of cybersecurity measures to thwart such phishing attempts in the crypto space.

