logo

Android Malware Targets Indian Banking Users to Steal Financial Info and Mine Crypto

ID: 8483e816-0948-5a31-b214-cf2e47ae2b33

STIX ID: report--8483e816-0948-5a31-b214-cf2e47ae2b33

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2025-08-04

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research details an Android malware campaign targeting Hindi-speaking users (primarily in India) that lures victims with phishing sites impersonating banks to install a dropper APK; the dropper dynamically loads a second-stage payload that harvests cardholder data and, upon receiving specific Firebase Cloud Messaging commands, executes a Monero mining binary (XMRig-compatible) in the background. The report provides technical analysis of the two-stage loader, execution of an encrypted native miner, telemetry showing infections concentrated in India, a set of IOCs (APK hashes, phishing URLs, FCM account), and user-focused mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.