Full Report
In this article, Group-IB specialists uncovered a large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions through the UniApp framework, and distributed through official app stores and phishing sites.
Analysis Summary
# Incident Report: Large-Scale Fraud Campaign via UniApp Framework
## Executive Summary
Group-IB specialists uncovered a widespread fraud campaign targeting iOS and Android users globally. Attackers utilized the UniApp framework to deploy fake trading applications distributed through a combination of phishing websites and official app stores (Apple App Store and Google Play). The campaign aimed to steal financial assets by tricking victims into "investing" through fraudulent platforms that simulated market gains but prevented withdrawals.
## Incident Details
- **Discovery Date:** May 2024 (based on public reporting)
- **Incident Date:** Ongoing (active through late 2023 and 2024)
- **Affected Organization:** Multiple retail investors (end-users)
- **Sector:** Finance / Cryptocurrency / Retail Trading
- **Geography:** Multiple regions (Asia-Pacific, Europe, Middle East, and Latin America)
## Timeline of Events
### Initial Access
- **Date/Time:** Variable (Campaign active throughout 2024)
- **Vector:** Phishing, Social Engineering, and Official App Store listings.
- **Details:** Attackers initiated contact via social media, dating apps, and messaging platforms (e.g., WhatsApp, Telegram). They directed victims to phishing sites or official app stores to download fake trading apps.
### Lateral Movement
- **N/A:** As this is a mobile fraud campaign targeting consumers, the "movement" involved psychological manipulation (social engineering) to move the victim from a chat platform to a malicious application and finally to a fake investment portal.
### Data Exfiltration/Impact
- **Details:** Personal Identifiable Information (PII) was collected during registration. Financial impact occurred when victims deposited funds (cryptocurrency or fiat) into the apps, which were then transferred to attacker-controlled wallets.
### Detection & Response
- **Detection:** Discovered by Group-IB researchers through threat hunting and analysis of suspicious mobile applications using the UniApp framework.
- **Response Actions:** Reporting of malicious applications to Google and Apple for removal; identification and defanging of phishing domains; public dissemination of indicators of compromise (IOCs).
## Attack Methodology
- **Initial Access:** Social engineering (romance scams/pig butchering), phishing websites, and bypassing app store review processes.
- **Persistence:** Installation of a mobile application on the victim's device; use of the UniApp framework to facilitate cross-platform deployment.
- **Privilege Escalation:** Not applicable; relied on user-granted permissions during app installation.
- **Defense Evasion:** Use of legitimate frameworks (UniApp) to hide malicious intent; hosting initial "dummy" versions of apps on official stores that were later updated or redirected to fraud portals.
- **Credential Access:** Theft of login credentials via fake registration and login screens within the apps.
- **Discovery:** Identifying high-net-worth targets via social media profiling.
- **Lateral Movement:** N/A (Client-side attack).
- **Collection:** Gathering of user financial data, ID documents for "KYC" purposes, and deposit information.
- **Exfiltration:** Direct transfer of victim funds to attacker-controlled accounts.
- **Impact:** Financial loss and identity theft for thousands of users.
## Impact Assessment
- **Financial:** Significant; large-scale theft of individual investments (exact total volume undisclosed but estimated in the millions).
- **Data Breach:** Compromise of personal documents (Passports/IDs) and financial credentials.
- **Operational:** Disruption of legitimate trading platform reputations due to brand impersonation.
- **Reputational:** Erosion of trust in official app store vetting processes.
## Indicators of Compromise
### Network Indicators
- hXXps://www.upstoxcalculator[.]com
- hXXps://www.yupstocks[.]com/h5/#/login
- hXXps://a.gold-blockchain[.]cc/app/home/getH5
### File Indicators (SHA-1 Hashes)
- e74392a807f0ad180c6a80aafd198b7ef4ad0581
- 0e2f85f1c7705e795ed9c2491ce628fac411fcfc
- 0179e333287fe6d87a76f4b4d90602f54e833379
- cfae03202181664723a2133fda7e74079b0e5f0e
- 34f93e7e4d74852c647978e3195a1de79eaba3ff
- 8b2fdbc0050b9840c404a49373d802586acc82ea
## Response Actions
- **Containment:** Flagging and takedown requests for the identified domains.
- **Eradication:** Working with Apple and Google to remove the UniApp-based fraud apps from stores.
- **Recovery:** Educating users through security advisories to prevent further deposits.
## Lessons Learned
- Attackers are increasingly using cross-platform frameworks (like UniApp) to develop malicious apps quickly for both iOS and Android.
- The presence of an app on an official store (Apple/Google) does not guarantee its legitimacy.
- Social engineering remains the primary driver for high-value financial fraud.
## Recommendations
- **For Organizations:** Use Digital Risk Protection (DRP) services to monitor for brand impersonation and fake apps.
- **For Users:**
- Verify app developers and read reviews before downloading.
- Avoid investment advice from strangers met on social media or dating apps.
- Never share sensitive PII or financial data with unverified platforms.
- Use two-factor authentication (2FA) on all financial accounts.