The post Hackers spoof Google Play Store pages to mine crypto appeared on BitcoinEthereumNews.com. Hackers are targeting victims via a new phishing scheme. AccordingThe post Hackers spoof Google Play Store pages to mine crypto appeared on BitcoinEthereumNews.com. Hackers are targeting victims via a new phishing scheme. According

Hackers spoof Google Play Store pages to mine crypto

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Hackers are targeting victims via a new phishing scheme. According to a post from SecureList, hackers are using fake Google Play Store pages to spread an Android malware campaign in Brazil.

The harmful app appears to be a legitimate download, but once installed, it converts infected phones into crypto mining machines. Moreover, it is used to install banking malware and grant remote access to threat actors.

Hackers turn Brazilian smartphones into crypto mining machines

The campaign starts on a phishing website that looks almost identical to Google Play. One of the pages offers a fake app called INSS Reembolso, which claims to be linked to Brazil’s social security service. The UX/UI design copies a trusted government service and the Play Store layout to make the download appear safe.

After installing the fake app, the malware unpacks hidden code in multiple stages. It uses encrypted components and loads the main malicious code directly into memory. There are no visible files on the device, making it hard for users to detect any suspicious activity.

The malware also evades analysis by security researchers. It checks whether the phone is running in an emulated environment. If it detects one, it stops working.

After successful installation, the malware continues to pull down more malicious files. It shows another fake Google Play-style screen, then displays a false update prompt and pushes the user to tap the update button.

One of those files is a crypto miner, which is a version of XMRig compiled for ARM devices. The malware fetches the mining payload from attacker-controlled infrastructure. Then it decrypts it and runs it on the phone. The payload connects infected devices to mining servers controlled by the attackers to mine crypto silently in the background.

The malware is sophisticated and does not mine crypto blindly. According to SecureList’s analysis, the malware monitors the battery charge percentage, temperature, installation age, and whether the phone is being actively used. Mining starts or stops based on the monitored data. The goal is to stay hidden and reduce any chance of detection.

Android kills background apps to save battery, but the malware evades this by looping an almost silent audio file. It fakes active use to avoid Android’s auto-deactivation.

To continue sending commands, the malware uses Firebase Cloud Messaging, which is a legitimate Google service. This makes it easy for attackers to send new instructions and manage activity on the infected device.

Banking Trojan targets USDT transfers

The malware does more than mine coins. Some versions also install a banking Trojan that targets Binance and Trust Wallet, especially during USDT transfers. It overlays fake screens on top of the real apps, then it quietly replaces the wallet address with one controlled by the attacker.

The banking module also monitors browsers like Chrome and Brave and supports a wide range of remote commands. These include recording audio, capturing screens, sending SMS messages, locking the device, wiping data, and logging keystrokes.

Fake overlay pages from Binance (left) and Trust Wallet (right). Source: SecureList.

Other recent samples keep the same fake app delivery method but switch to a different payload. They install BTMOB RAT, a remote access tool sold in underground markets.

BTMOB is part of a malware-as-a-Service (MaaS) ecosystem. Attackers can buy or rent it, which lowers the barrier to hacking and theft. The tool gives attackers deeper access, including screen recording, camera access, GPS tracking, and credential theft.

BTMOB is actively promoted online. A threat actor shared demos of the malware on YouTube, showing how to control infected devices. Sales and support are handled through a Telegram account.

SecureList stated that all known victims are in Brazil. Some newer variants are also spreading through WhatsApp and other phishing pages.

Sophisticated hacking campaigns like this are reminders to verify everything and trust nothing.

Source: https://www.cryptopolitan.com/hackers-spoof-google-play-to-mine-crypto/

Market Opportunity
TAP Protocol Logo
TAP Protocol Price(TAP)
$0.1068
$0.1068$0.1068
+1.90%
USD
TAP Protocol (TAP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

The post UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future appeared on BitcoinEthereumNews.com. Key Highlights Microsoft and Google pledge billions as part of UK US tech partnership Nvidia to deploy 120,000 GPUs with British firm Nscale in Project Stargate Deal positions UK as an innovation hub rivaling global tech powers UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future The UK and the US have signed a “Technological Prosperity Agreement” that paves the way for joint projects in artificial intelligence, quantum computing, and nuclear energy, according to Reuters. Donald Trump and King Charles review the guard of honour at Windsor Castle, 17 September 2025. Image: Kirsty Wigglesworth/Reuters The agreement was unveiled ahead of U.S. President Donald Trump’s second state visit to the UK, marking a historic moment in transatlantic technology cooperation. Billions Flow Into the UK Tech Sector As part of the deal, major American corporations pledged to invest $42 billion in the UK. Microsoft leads with a $30 billion investment to expand cloud and AI infrastructure, including the construction of a new supercomputer in Loughton. Nvidia will deploy 120,000 GPUs, including up to 60,000 Grace Blackwell Ultra chips—in partnership with the British company Nscale as part of Project Stargate. Google is contributing $6.8 billion to build a data center in Waltham Cross and expand DeepMind research. Other companies are joining as well. CoreWeave announced a $3.4 billion investment in data centers, while Salesforce, Scale AI, BlackRock, Oracle, and AWS confirmed additional investments ranging from hundreds of millions to several billion dollars. UK Positions Itself as a Global Innovation Hub British Prime Minister Keir Starmer said the deal could impact millions of lives across the Atlantic. He stressed that the UK aims to position itself as an investment hub with lighter regulations than the European Union. Nvidia spokesman David Hogan noted the significance of the agreement, saying it would…
Share
BitcoinEthereumNews2025/09/18 02:22
‪Pundit Reveals Outlook for XRP, BNB, Solana, Cardano, DOGE In The Coming Years with Bullish Expectations ‬ ⋆ ZyCrypto

‪Pundit Reveals Outlook for XRP, BNB, Solana, Cardano, DOGE In The Coming Years with Bullish Expectations ‬ ⋆ ZyCrypto

The post ‪Pundit Reveals Outlook for XRP, BNB, Solana, Cardano, DOGE In The Coming Years with Bullish Expectations ‬ ⋆ ZyCrypto appeared on BitcoinEthereumNews.
Share
BitcoinEthereumNews2026/03/23 01:23
BlockchainFX or Based Eggman $GGs Presale: Which 2025 Crypto Presale Is Traders’ Top Pick?

BlockchainFX or Based Eggman $GGs Presale: Which 2025 Crypto Presale Is Traders’ Top Pick?

Traders compare Blockchain FX and Based Eggman ($GGs) as token presales compete for attention. Explore which presale crypto stands out in the 2025 crypto presale list and attracts whale capital.
Share
Blockchainreporter2025/09/18 00:30