Group-IB also warns that the UniShadow Trade apps can mimick a variety of legitimate cryptocurrency and trading platforms
The apps requested that users uploaded several documents, such as national IDs and passports, both to add legitimacy to the investment process and also to further empower the threat actors with sensitive information theft.
Even when legitimate it is pretty creepy when crypto exchanges ask for this stuff, there's no reason they would need it except to surveil you for the government and it's an obvious security risk. Hadn't considered that it also normalizes giving sensitive information to scammers who also ask for it apparently.