Beware of fake Poloniex apps!
Two troublesome apps on the Google Play Store created to spoof account information targeted users of popular Bitcoin exchange Poloniex. These fake apps look like they are official apps from Poloniex. The apps not only capture account information by prompting them to sign in to Poloniex, but also ask users to access their Gmail accounts.
The two apps have been on the Google Play Store for a while.. They were later deleted from the platform after they were reported to Google.
Target new users
Poloniex is one of the top Bitcoin exchanges with over a hundred digital currencies users can trade. Its popularity is the primary reason its users are the target of scammers.. As the popularity of digital currencies increased, many newcomers fell into the traps.. This is of course due to the lack of knowledge about digital currency and its trading. Users who are new to the world of digital currencies usually fall into the trap of these fake applications.
The first application reached 5 thousand users
The first of the above-mentioned applications was August 28, 2017 and 19 It was included in the Google Play Store under the name “POLONIEX” between September 2017. Also, the developer name was “Poloniex”.. Although the application received bad reviews, it was installed by approximately 5 thousand users.
500 people downloaded the second application
The second application leaked to the Play Store, “POLONIEX EXCHANGE” under the developer name of “POLONIEX COMPANY” published under the title. The app has been downloaded by nearly 500 people when it was launched on October 15, 2017.
These apps offer a design and good functionality as if it were an official app to gain users’ trust.. It is often not easy to find out that it is fake.
Attack starts when the application is opened
Account information capture begins when the application is launched. A fake screen prompts users to enter their Poloniex information. After the user enters the requested information, this information is sent directly to the attackers. After the attackers get their account information, their next target is to get their email information.. Often users are asked to sign in with their Google account for a “Two-step security check”. These apps also have control over their inbox if they are accidentally granted access to emails during sign-in. can delete all notifications and perform actions that require email. This means full control of the account.
Use Google Authenticator
Reduces risk from offensive apps if user is using two-factor authentication. Based on the Poloniex example, if you use Google Authenticator on this exchange, your account will be safe.. Always make sure two factor authentication service is enabled. Also, if you think you’ve been hacked by fake apps, change your Poloniex and email account login information immediately.
Current Hedget guide: What is HGET coin? Comprehensive fundamental analysis