{"id":2628,"date":"2024-02-29T13:30:00","date_gmt":"2024-02-29T13:30:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/xhelper-all-in-one-android-app-global-money-laundering"},"modified":"2024-02-29T13:30:00","modified_gmt":"2024-02-29T13:30:00","slug":"meet-xhelper-the-all-in-one-android-app-for-global-money-laundering","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/29\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering\/","title":{"rendered":"Meet &#8216;XHelper,&#8217; the All-in-One Android App for Global Money Laundering"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt9118494239f7b189\/64f159fd96efc91dee2f8eb7\/Moneylaundering_ronstik_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybercriminals are laundering stolen funds through ordinary people, thanks to a small ecosystem of user-friendly apps that can turn any mobile user into an unwitting money mule.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A new report from Cloud SEK details one such app: &#8220;XHelper,&#8221; an Android platform that connects scammers with citizens of India, whose job is to quickly receive and pass on stolen funds to shadowy third-parties. It sports a clean, user-friendly interface that makes the entire process rather simple, and serves to obscure both the nature of the payments, and who&#8217;s on the other end of each transaction.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The app is enabling <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/pig-butchering-investment-scams-3b-cybercrime-threat-overtaking-bec\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">pig butchering<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, task, loan, and ecommerce scams, and illegal gambling operations, at a massive scale. It currently sports around 37,000 active users with around 16,000 verified bank accounts, and moves a massive 160 million rupees per day (just under US $2 million).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And besides XHelper, CloudSEK researcher Sparsh Kulshehtra notes, &#8220;Our research has identified similar schemes in other countries, highlighting the need for a united front against money laundering using unsuspecting individuals.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How XHelper Works\">How XHelper Works<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last summer, Chinese cybercriminals caught around <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/assets-global.website-files.com\/635e632477408d12d1811a64\/65320d7ba79c7763af31cd3e_Loan%20Apps%20Report_Final.pdf\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">40,000 individuals in five continents<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in a loan scam. To obscure so many ill-gotten earnings, they called upon a network of hundreds of thousands of online payment accounts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This was how researchers first caught whiff that, besides the scam itself, something underneath it was deeply wrong, too. It led them to XHelper, an app designed not just to hide the sources of money, but also its own purpose from its users.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">XHelper is distributed online by fake &#8220;money transfer&#8221; businesses. New members are recruited by &#8220;agents&#8221; \u2014 individuals on Telegram posing as representatives of successful businesses, which need help managing their high volumes of daily transactions. Agents earn bonuses for each new recruit so that the laundering network grows larger and larger and, therefore, more robust.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like any other gig economy app, recruits register their (payment) information and then begin taking on jobs: in this case, receiving money from one party, and within minutes passing it on to another.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Users earn a cut of the spoils (between 0.2-0.3%), which scales as they complete more jobs, earn good ratings for them, and add more bank accounts. Beginner users might only move 10,000 or 20,000 rupees a day via one or two bank accounts, and earn a few hundred rupees (less than five dollars) for their troubles. The highest-level users move tens of millions in an average day, and earn back thousands. The app&#8217;s top three users \u2014 &#8220;shahbaz,&#8221; &#8220;Register26,&#8221; and &#8220;Ranjan1982&#8221; \u2014 have earned themselves more than 12 million rupees (~$145,000) and counting.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Can Money Mules Be Stopped?\">Can Money Mules Be Stopped?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That regular people are executing large volumes of near-instant money transfers begs the question: Why aren&#8217;t they getting caught?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Firstly, the app offers a series of helpful tutorials that cover not just how to use its various features \u2014 accompanied by cheery stock music \u2014 but also how to deal with adverse situations, scored by eerie, more somber tunes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most important of them all is a tutorial that guides users in registering corporate bank accounts, by posing as small businesses. These corporate accounts enable them to process high volumes of transactions without raising the kinds of red flags that the same activity would in a personal account.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mules also have other tricks at their disposal, like using different payment systems for incoming and outgoing transfers. &#8220;While funds may enter the mule&#8217;s account through UPI (a popular Indian payment system), the app instructs them to transfer them out via IMPS (Immediate Payment Service) [an Indian interbank transaction system]. This layering of transfer methods could be an attempt by criminals to obfuscate the transaction history and evade detection by the flagging mechanisms,&#8221; Kulshehtra explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To identify and curb this behavior, Kulshehtra says, banks, governments, and regulators <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/how-cybercriminals-are-operationalizing-money-laundering-and-what-to-do-about-it\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">all have a role to play<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, as do the organizations targeted by these scams.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Educating employees and customers through training and awareness campaigns empowers them to recognize and avoid these schemes. This combined focus on understanding the threat, strengthening internal defenses, and building user awareness creates a robust shield against cyber scams,&#8221; he concludes.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/xhelper-all-in-one-android-app-global-money-laundering\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are laundering stolen funds through ordinary people, thanks to<\/p>\n","protected":false},"author":12,"featured_media":2629,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2628","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=1200%2C800&ssl=1",1200,800,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=1200%2C800&ssl=1",1200,800,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=1200%2C800&ssl=1",1200,800,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/meet-xhelper-the-all-in-one-android-app-for-global-money-laundering.jpg?fit=1200%2C800&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2628"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2628\/revisions"}],"predecessor-version":[{"id":2631,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2628\/revisions\/2631"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2629"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}