HomeSecuritySEEDSNATCHER: Android malware steals data and crypto wallets

SEEDSNATCHER: Android malware steals data and crypto wallets

A new, dangerous threat is making its appearance in the cryptocurrency, targeting Android users globally. SeedSnatcher, camouflaged behind the innocent app name “Coin”, is distributed via Telegram and is designed solely to extract digital wallet recovery phrases, while also allowing its operators to execute remote commands on infected devices.

SEEDSNATCHER Android malware

An organized and technically mature ecosystem

SeedSnatcher, with an installation package of com.pureabuladon.auxes, does not operate as a standalone malware, but is part of a well-organized campaign with a structure reminiscent of a professional criminal organization. The promotional teams use unique IDs to track installations, victims, and revenue, creating a commission network reminiscent of an affiliate model.

Cyfirma analysts revealed that the malware constantly communicates with its C2 server via WebSocket at apivbe685jf829jf[.]a2decxd8syw7k[.]top , which allows the attacker to receive and execute commands in real time . The attackers’ management screens already show many infected devices , indicating that the ecosystem is in full production mode.

See also: “Sryxen” malware manages to bypass Chrome encryption

The "quiet" seizure of the device

One of SeedSnatcher's biggest strengths is the way it circumvents Android's security. It initially requests minimal permissions – such as access to SMS – to avoid arousing suspicion. Once installed, it begins to escalate its privileges, leveraging Android processes to gain access to critical data and device functions.

Its internal architecture utilizes:

  • dynamic class loading,
  • stealthy WebView content injection,
  • commands and functions encoded as numbers instead of descriptions.

This obfuscation makes detection by security systems significantly more difficult, while allowing the malware to remain active without any visible signs.

Suspicious roots and professionalism

The indications are that the attackers are Chinese or at least speak Chinese, as all the environment screens analyzed are entirely in Chinese. The overall infrastructure indicates an organization with significant resources, technical training, and a clear financial motive.

The distribution model, infrastructure mechanisms, use of affiliate tracking, and number of infected victims all add up to a large-scale campaign aimed at the systematic theft of digital assets.

See also: Aisuru botnet behind 29.7 Tbps DDoS attack

SEEDSNATCHER: Android malware steals data and crypto wallets

Spoofed Wallet Interfaces: SeedSnatcher's Big Trap

SeedSnatcher's most powerful weapon is its highly realistic spoofing of popular crypto wallet. The malware detects which wallet application the user is opening and activates a fake overlay screen, designed to look exactly like the real one.

The wallets it targets include:
Trust Wallet, MetaMask, TokenPocket, imToken, Coinbase Wallet, TronLink, Binance Chain Wallet, OKX Wallet, and others.

In the case of Trust Wallet, SeedSnatcher even copies the actual package name (com.wallet.crypto.trustapp), using identical UI elements to avoid any suspicion.

The result? The user believes they are in the legitimate application and enters their seed phrase — essentially handing over their wallet to the attacker.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

BIP39: The ultimate deception technique

Unlike other malware that simply records what is typed, SeedSnatcher implements a full validation system . It loads the entire wordlist of valid words and checks in real time whether the mnemonic phrase entered by the victim is valid.

This means that attackers receive correct, fully functional seed codes, ready for immediate entry – without errors or failed recovery attempts. Thus, fund transfers are carried out quickly, silently and without the possibility of reversal.

See also: Hackers use Evilginx to steal session cookies and bypass MFA

SEEDSNATCHER: Android malware steals data and crypto wallets

One of the most dangerous mobile crypto stealers today

Once the recovery phrase reaches the attackers' server, the perpetrators gain full control of the wallet. The digital assets are transferred to their own addresses without the possibility of recovery by the victim.

The combination of technical complexity, UI spoofing, and full BIP39 validation makes SeedSnatcher one of the most threatening forms of mobile malware to ever target the crypto community.

In an era where users are increasingly managing their funds from their mobile phones, SeedSnatcher demonstrates how easily a device can become the weakest link – and how critical it is to be vigilant against apps that promise “tools” but hide traps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS