Cherryblos

Malware updated 4 days ago (2024-11-29T14:18:40.914Z)
Download STIX
Preview STIX
CherryBlos is a malicious software (malware) that primarily targets Android devices, with the primary objective of stealing cryptocurrency data. It was discovered in July 2023 when researchers found users unknowingly installing this crypto-stealing malware via the Google Play Store, often immediately after downloading a cryptocurrency mining application known as SynthNet. The cybercriminals behind CherryBlos cleverly disguised the malware as this legitimate app, thereby deceiving users into unintentionally compromising their own security. The unique and alarming aspect of CherryBlos malware is its utilization of optical character recognition (OCR). This technology enables it to extract sensitive information from pictures saved on the infected device. Specifically, it targets images that contain data related to the user's cryptocurrency wallets. By leveraging OCR, CherryBlos can access and steal this crucial information, posing a significant threat to users' digital assets. Given the serious threat posed by CherryBlos and similar malware like FakeTrade, it is recommended that users exercise extreme caution while downloading apps, particularly those related to cryptocurrency. Users should also restrict sharing files or photos unless necessary and maintain robust password protection. Trend Micro, a global leader in cybersecurity solutions, has identified several malicious Android apps containing CherryBlos malware, highlighting the importance of using trusted sources for app downloads.
Description last updated: 2024-05-04T19:22:53.359Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Faketrade is a possible alias for Cherryblos. FakeTrade is a malicious software, or malware, that was first identified in 2021. It infiltrates Android devices through fraudulent money-earning apps uploaded on Google Play, and has been primarily linked with the app “com.mramyr.myrapp.” The malware was named "FakeTrade" due to its association wit
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Android
Phishing
Scams
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.