TLDR: Hackers are using fake Google Play Store pages in Brazil to distribute malware disguised as legitimate apps. The malware runs XMRig on infected Android devicesTLDR: Hackers are using fake Google Play Store pages in Brazil to distribute malware disguised as legitimate apps. The malware runs XMRig on infected Android devices

Hackers Use Fake Google Play Pages to Spread Crypto Mining Malware Across Brazil

2026/03/22 23:45
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

TLDR:

  • Hackers are using fake Google Play Store pages in Brazil to distribute malware disguised as legitimate apps.
  • The malware runs XMRig on infected Android devices, silently mining crypto while avoiding battery detection.
  • A banking Trojan targets Binance and Trust Wallet, replacing wallet addresses during live USDT transactions.
  • BTMOB RAT, a malware-as-a-service tool, gives attackers camera, GPS, and credential access on infected phones.

Android malware is spreading across Brazil through counterfeit Google Play Store pages, according to a new report by SecureList.

Hackers are using phishing websites to distribute apps that appear legitimate. Once installed, these apps silently convert infected phones into crypto mining devices.

Some variants also deploy a banking Trojan. The campaign currently targets Brazilian users exclusively, with newer versions spreading through WhatsApp and additional phishing channels.

Fake App Turns Phones Into Crypto Mining Machines

The campaign starts with a phishing website that closely mimics the Google Play Store. One of the fake apps is called INSS Reembolso, which claims to be tied to Brazil’s social security service.

The design copies trusted government branding and the Play Store layout, making the download appear safe to unsuspecting users.

After a user installs the fake app, the malware begins unpacking hidden code through multiple stages. It uses encrypted components and loads the main malicious code directly into the phone’s memory.

SecureList noted that “there are no visible files on the device, making it hard for users to detect any suspicious activity.”

The malware also takes steps to evade detection by security researchers. It checks whether the phone is running in an emulated environment and stops all activity if it detects one.

This evasion technique makes it harder to analyze in a lab setting. Android normally kills background apps to save battery, but the malware loops a silent audio file to fake active use.

Once the malware is fully active, it fetches a crypto mining payload from attacker-controlled infrastructure. This payload is a version of XMRig compiled for ARM devices, which are common in Android smartphones.

The infected device connects to mining servers and mines cryptocurrency silently in the background. According to SecureList, “the malware monitors the battery charge percentage, temperature, installation age, and whether the phone is being actively used,” with mining starting or stopping based on that data.

Banking Trojan Targets Binance and Trust Wallet Users

Beyond crypto mining, some versions of the malware install a banking Trojan that targets Binance and Trust Wallet.

During USDT transfers, the Trojan overlays fake screens on top of the real apps. It then quietly replaces the recipient wallet address with one controlled by the attacker.

The banking module also monitors popular browsers, including Chrome and Brave. SecureList confirmed the module “supports a wide range of remote commands,” including screen recording, audio capture, SMS sending, keystroke logging, device locking, and data wiping.

It additionally uses Firebase Cloud Messaging to receive instructions from attackers. All of these actions are carried out remotely without the user’s knowledge.

Other recent samples use the same fake app delivery method but switch the payload to BTMOB RAT. This remote access tool is sold in underground markets as part of a malware-as-a-service ecosystem. It provides deeper access, including camera control, GPS tracking, and credential theft.

SecureList confirmed that “all known victims are in Brazil,” though newer variants are also spreading through WhatsApp and other phishing pages.

BTMOB is actively promoted across online platforms, including YouTube and Telegram. Sales and support are handled through a dedicated Telegram account, which lowers the barrier for less-skilled attackers.

The post Hackers Use Fake Google Play Pages to Spread Crypto Mining Malware Across Brazil appeared first on Blockonomi.

Opportunità di mercato
Logo Battery
Valore Battery (BATTERY)
$0.0001349
$0.0001349$0.0001349
-0.44%
USD
Grafico dei prezzi in tempo reale di Battery (BATTERY)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Condividi
BitcoinEthereumNews2025/09/18 00:36
Pastor Involved in High-Stakes Crypto Fraud

Pastor Involved in High-Stakes Crypto Fraud

A gripping tale of deception has captured the media’s spotlight, especially in foreign outlets, centering on a cryptocurrency fraud case from Denver, Colorado. Eli Regalado, a pastor, alongside his wife Kaitlyn, was convicted, but what makes this case particularly intriguing is their unconventional defense.Continue Reading:Pastor Involved in High-Stakes Crypto Fraud
Condividi
Coinstats2025/09/18 00:38
The co-founder of CoinDCX was arrested by Indian police on suspicion of fraud; the exchange claims it was a fake website impersonating him.

The co-founder of CoinDCX was arrested by Indian police on suspicion of fraud; the exchange claims it was a fake website impersonating him.

PANews reported on March 23 that, according to The Block, Sumit Gupta and Neeraj Khandelwal, co-founders of CoinDCX, India's largest cryptocurrency exchange, were
Condividi
PANews2026/03/23 08:22