Bitcoin Forum
May 22, 2024, 04:00:11 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: PSA: Wallet stealing versions of MultiBit and Schildbach Bitcoin Wallet  (Read 4772 times)
jim618 (OP)
Legendary
*
Offline Offline

Activity: 1708
Merit: 1066



View Profile WWW
April 26, 2013, 10:05:48 PM
 #1

In the last 24 hours a fake version of the multibit.org site with wallet stealing code has appeared. I have confirmed it is a wallet stealer by decompiling the code.

Andreas Schildbach has just noticed a similar looking scam version of his Bitcoin Wallet on Google Play.

Be very careful with any MultiBit and Schildbach Bitcoin Wallet downloads.

Only download MultiBit from:
https://multibit.org

Andreas has confirmed that the correct URL for his wallet is:
https://play.google.com/store/apps/details?id=de.schildbach.wallet

MultiBit HD   Lightweight desktop client.                    Bitcoin Solutions Ltd   Bespoke software. Consultancy.
Andreas Schildbach
Hero Member
*****
Offline Offline

Activity: 483
Merit: 501


View Profile
April 26, 2013, 10:15:25 PM
 #2

To be clear, so far I have no proof that the Bitcoin Wallet clone in question has any malicious code.

However, the fact that the publisher chose to copy-protect his APK file makes me skeptical. If anyone is able to extract copy-protected APKs from Google Play, please drop me a mail.

And to be even more clear: I'm not talking about Litecoin Wallet or the Blockchain.info wallet. They are both legitimate clones as far as I can tell.
qxzn
Hero Member
*****
Offline Offline

Activity: 609
Merit: 505



View Profile
April 26, 2013, 10:40:04 PM
 #3

In the last 24 hours a fake version of the multibit.org site with wallet stealing code has appeared. I have confirmed it is a wallet stealer by decompiling the code.

Andreas Schildbach has just noticed a similar looking scam version of his Bitcoin Wallet on Google Play.

Be very careful with any MultiBit and Schildbach Bitcoin Wallet downloads.

Only download MultiBit from:
https://multibit.org

Andreas has confirmed that the correct URL for his wallet is:
https://play.google.com/store/apps/details?id=de.schildbach.wallet

How is the wallet-stealing client being distributed?
jim618 (OP)
Legendary
*
Offline Offline

Activity: 1708
Merit: 1066



View Profile WWW
April 27, 2013, 05:51:32 AM
Last edit: April 27, 2013, 08:02:52 AM by jim618
 #4

For MultiBit - where the code is confirmed to be a wallet
stealer - there is:
+ a site that is a rip of an old multibit.org site with the download links for Linux and Windows pointing to the malware. I won't mention the site name but it is basically a name squat ie a few characters different to multibit.org
+ they were running a Google ads campaign along the lines of 'Secure desktop Bitcoin wallet . . .' this should now have been pulled. MultiBit does not run any Google ads so any you see are a scam.
+ there was also a r/bitcoin posting on Thursday night that pretended to be a 'MultiBit desktop ticker v2.1' with a link to mediafire to download.  This product does not exist and I would never put a random download link like that. This post has now been deleted.

The malware is a copy of the MultiBit code base ie you have an installer that installs a fake MultiBit and it looks pretty normal. When the fake MultiBit starts up it starts a thread that regularly does a HTTP GET to their command and control server with the balance of your wallet. It then returns either a list of addresses (and sends your bitcoin to one at random) or no addresses, in which case the steal will be delayed until later.

As Andreas points out it is not 100% confirmed the clone of his code on Google Play is a wallet stealer but it looks very similar: a rip of his app description, name squatting domain etc. It seems prudent to assume it contains the same wallet stealing code.

There may be other methods the authors are using to try to distribute it but those are the ones we are aware of.

MultiBit HD   Lightweight desktop client.                    Bitcoin Solutions Ltd   Bespoke software. Consultancy.
crazy_rabbit
Legendary
*
Offline Offline

Activity: 1204
Merit: 1001


RUM AND CARROTS: A PIRATE LIFE FOR ME


View Profile
April 27, 2013, 06:07:54 AM
 #5

Crap- this is bad news. I think we are going to see more and more of this in the future. :-/


EDIT: Maybe there needs to be a verified repository of bitcoin software. (as much as that sounds like centralization)

more or less retired.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!