logo

MiningDropper Spreads Infostealers, RATs, Banking Malware on Android

ID: 3d3796a1-8c9f-5262-b715-1113a34c9794

STIX ID: report--3d3796a1-8c9f-5262-b715-1113a34c9794

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

MiningDropper is a sophisticated, multi-stage Android dropper framework distributed via trojanized apps and phishing links that first loads XOR-obfuscated native code to decrypt staged DEX payloads and then installs crypto miners or high-impact user payloads (infostealers, BTMOB RAT, banking trojans). The report details obfuscation (XOR, AES, dynamic DEX), anti-emulation checks, split-APK reconstruction, campaign targeting (India, Asia, Europe, LATAM), and telemetry of over 1,500 low-AV-detected samples, underscoring active, large-scale abuse and the need for behavioral detection and MDM controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.