Kaspersky says Egypt accounts for 31% of cyber-attacks disguised as dating apps

Kaspersky’s analysis has shown that within 2019 the Middle East region saw a circulation of 658 threats disguised as more than 20 popular dating applications, with 2,082 attacks on 1,352 users detected.

The countries attacked most often were Egypt, accounting for 31 percent of all attacks in the region, followed by Saudi Arabia and the UAE, which represent 18 percent and 17 percent, respectively, Kaspersky said.

As Valentine’s Day due this Friday, singles and couples alike are under intensifying pressure to solidify their plans for this day. While choosing the right partner is a matter of paramount importance, Kaspersky advised that there is another matter that should be treated with care.

Popular dating services used across the globe, such as Tinder, Bumble, or Zoosk, often become a bait used to spread mobile malware or retrieve personal data to later bombard the users with unwanted ads or even spend their money on expensive paid subscriptions. Such files have nothing to do with legitimate apps, as they only use a name and sometimes copy a design of authentic dating services.

Cybercriminals would most often choose Tinder to cover their files: this app’s name was used in nearly the third of all cases 693 attacks detected in the Middle East region. However, the researchers noticed that around 13 percent of attacks in the region came from the apps disguised as local services for solely Arab matchmaking.

The danger these malicious files bring varies from file to file, ranging from Trojans that can download other malware to ones that send expensive SMS, to adware, making it likely every ping a user gets is some sort of annoying ad notification rather than a message from a potential date.

For instance, one of the applications that at first glance looks like Tinder is, in fact, a banking Trojan that constantly requests Accessibility service rights, and upon getting them, grants itself all rights necessary to steal money from the user. Another names itself as ‘Settings’ right after installation, shows a fake ‘error’ message and later disappears, with a high likelihood it will return with unwanted ads a few days later.

Cybercriminals who specialise in phishing also do not miss the chance to feed on those seeking to find love. Fake copies of popular dating applications and websites, such as Match.com and Tinder, flood the internet. Users are required to leave their personal data or connect to the applications via their social media account. The result is not surprising: the data will later be used or sold by cybercriminals, while the user will be left with nothing.

“Love is one of those topics that interests people universally, and, of course, that means that cybercriminals are also there. Online dating has made our lives easier and yet uncovered new risks on the path to love.” Vladimir Kuskov, head of advanced threat research and software classification at Kaspersky, said.

“We advise users to stay attentive and use legal versions of applications that are available in official application stores. And, of course, we wish you best of luck finding the perfect date for this special day,” Kuskov added.

To avoid cyber risks ahead of Valentine’s Day, Kaspersky recommends:

  • Always checking application permissions to see what your installed apps are allowed to do
  • Not installing applications from untrusted sources, even if they are actively advertised, and block the installation of programs from unknown sources in your smartphone’s settings
  • Finding out more information about the dating website you are planning to visit: look into its reputation on the internet and try to find user feedback
  • Using a reliable security solution like Kaspersky Total Security that delivers advanced protection on Mac, as well as on PC and mobile devices

To use dating apps safely, Kaspersky recommends:

  • Avoiding sharing too much personal information with strangers
  • Making sure that the person you are meeting is real, as fraudsters often use fake profiles for scams