logo

Android Cryptojacker Disguised as Banking App Exploits Device Lock State

ID: a2094f9e-091c-5e49-b75f-b328716e403e

STIX ID: report--a2094f9e-091c-5e49-b75f-b328716e403e

Feed Name: Seqrite Blog

Threat Score
65/100

Date Published: 2025-07-18

Date Updated: 2026-04-30

Author: Digvijay Mane

...
...

This report analyzes an active Android cryptomining campaign that uses a phishing site (getxapp.in) and a fake banking app to install an XMRig-based miner: the app monitors device state, downloads an AES-encrypted native payload (libmine-arm32/64.so) from GitHub/Cloudflare/custom domains, decrypts and executes it as 'd-miner', and runs Monero mining jobs when the device is locked, causing high CPU/memory use, overheating, battery drain, and potential hardware damage; the report includes IOCs (URLs, pool domains, and wallet) and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.