July 7, 2021

Lookout Discovers Crypto Mining Scams Targeting Tens of Thousands of Victims Using Hundreds of Android Apps

San Francisco, California – July 7, 2021 Lookout, Inc., an integrated endpoint-to-cloud security company,today announced the discovery of major crypto mining scams using hundreds of Android apps. Categorized into two distinct Android app families, BitScam and CloudScam, these apps were designed to target people interested in cryptocurrencies. In total, security researchers at the Lookout Threat Lab identified more than 170 apps that are estimated to have scammed more than 93,000 victims. The majority of these apps are side loaded based on the fact that only 25 were available for download on Google Play. Lookout has been in close contact with Google and the apps on Play have been removed.

The BitScam and CloudScam apps advertise themselves as providing cloud cryptocurrency mining services for a fee. After analyzing the apps, Lookout researchers found that no cloud crypto mining actually takes place. The scammers pocket the money spent on apps and upgrades without ever delivering the promised services. Lookout estimated that the apps stole more than $350,000 from their victims.

“These apps were able to fly under the radar because they don’t actually do anything malicious,” said Ioannis Gasparis, a mobile application security researcher at Lookout. “They are simply shells set up to attract users caught up in the cryptocurrency craze and collect money for services that don’t exist. Purchasing goods or services online always requires a certain degree of trust — these scams prove that cryptocurrency is no exception.”

BitScam and CloudScam apps both trick people into thinking they are paying for cloud crypto mining services. In addition to the apps themselves costing money, they promote additional services and upgrades that users can purchase within the apps, either by transferring cryptocurrencies to the developers’ wallets or through Google Play. These apps also display fake minimum account balances to entice users to spend more money on the services and upgrades.

While the BitScam and CloudScam cryptomining apps have now been removed from Google Play, there are dozens more available for download on third-party app stores. 

To learn more about BitScam and CloudScam, read the Lookout research blog or visit the Lookout Threat Lab.

Additional Resources:

- To learn about Lookout research and how your organization can access the latest threat intelligence, visit the Lookout Threat Lab and the Lookout Threat Advisory Services.

- Sign up for a free trial of Lookout.

- Follow the Lookout blog and join the conversation on LinkedIn and Twitter.

Subscribe to the Lookout Endpoint Enigma podcast.

About Lookout

Lookout is an integrated endpoint-to-cloud security company. Our mission is to secure and empower our digital future in a privacy-focused world where mobility and cloud are essential to all we do for work and play. We enable consumers and employees to protect their data, and to securely stay connected without violating their privacy and trust. Lookout is trusted by millions of consumers, the largest enterprises and government agencies, and partners such as AT&T, Verizon, Vodafone, Microsoft, Google, and Apple. Headquartered in San Francisco, Lookout has offices in Amsterdam, Boston, London, Sydney, Tokyo, Toronto and Washington, D.C. To learn more, visit www.lookout.com and follow Lookout on its blog, LinkedIn, and Twitter.

Contact Lookout PR: press@lookout.com

Lookout press kit and media resources

Get the resources call_made