Malware (Fake Software Release)

Scammers create imitations of legitimate (d)apps (e.g. AtomicWallet or Trezor frontend app) to get victims to download it and send them their private keys or seed phrases or to get then to connect their wallets to a malicious smart contract by using the fake (d)app in order to drain their wallets.
Sub techniques (1)
IDName
RD05 Smart contract exploitation
IDMitigationDescription
M05Check links Users/investors should double check the links they press (e.g., have they changed since the last use?).
M10Check apps Users should check apps before downloading them. This can be accomplished by checking the download rate of the app in the app store as well as by analyzing available user ratings (beware fake ratings!).