A newly discovered Android malware, dubbed “SeedSnatcher”, has emerged as a serious threat to cryptocurrency users, capable of stealing seed phrases, personal data, and even remotely executing commands.
Identified by researchers at Cyfirma, the malware is disguised as an app named “Coin” with the package com.pureabuladon.auxes. It has been actively distributed through social platforms such as Telegram.
Advanced Capabilities and Crypto-Theft Mechanisms
SeedSnatcher is engineered to target cryptocurrency wallets with precision. Once installed, it requests basic permissions, such as SMS access, but later escalates its privileges to access contacts, call logs, files, and app usage statistics.
Its main objective is to steal crypto wallet seed phrases, achieved through realistic overlay attacks and phishing screens that imitate popular wallets, including Trust Wallet, MetaMask, TokenPocket, Coinbase Wallet, and Binance Chain Wallet.
The malware uses overlay permissions to draw fake “recover wallet” screens on top of legitimate apps. Enforcing BIP39 dictionary checks ensures victims enter valid mnemonic words, guaranteeing that attackers capture accurate, usable wallet seeds.
SeedSnatcher also supports integer-based C2 (command-and-control) operations; each command, ranging from 2000 to 2400, triggers different functions such as data collection, SMS reading, file exfiltration, or USSD execution.
To stay hidden, it maintains an encrypted WebSocket connection to its C2 domain, apivbe685jf829jf[.]a2decxd8syw7k[.]top, exchanging heartbeat “ping-pong” signals to remain active.
Persistence, Data Theft, and Organized Operation
Beyond wallet theft, SeedSnatcher performs broad-scale device surveillance. It harvests call logs, contacts, SMS messages, account details, and files from external storage.
Screenshots and gallery images are prioritized for exfiltration because they may contain sensitive data, such as password captures or crypto transactions.

The malware profiles the infected device by gathering metadata such as model, OS version, screen size, and IP address, allowing attackers to tailor subsequent actions.
Researchers uncovered a multi-affiliate distribution network behind the campaign. Each variant includes an agent-ID tracking system, letting promoters and affiliates be credited for successful installations a sign of an organized, financially motivated group.
The campaign’s development interface and instructions are written in Chinese, suggesting the operators originate from or are closely affiliated with the Chinese-speaking cybercrime ecosystem.
Cyfirma’s analysis concludes that SeedSnatcher represents a mature and scalable threat, combining stealth, social engineering, and advanced Android exploitation to enable full account takeovers and sustained financial theft.
Users are advised to download cryptocurrency apps only from official app stores, avoid sideloading APK files, and regularly monitor device permissions to mitigate this growing malware threat.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates