logo

The Silent Rhythm: How BeatBanker Malware Uses a Looping Audio File to Hijack Android Devices

ID: 588c5eb6-753f-51e5-a368-67abbba3801d

STIX ID: report--588c5eb6-753f-51e5-a368-67abbba3801d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-10

Date Updated: 2026-04-23

Author: Ddos

...
...

Kaspersky researchers uncovered BeatBanker, an Android malware campaign targeting Brazil that combines a discreet Monero miner with a banking Trojan that overlays Binance and Trust Wallet screens to intercept and tamper with transactions (replacing destination addresses). The malware persists using an almost-inaudible audio loop to avoid termination, monitors device state to time actions, and more recent variants replace the banking module with a BTMOB RAT; distribution is via phishing pages posing as the Play Store and via WhatsApp social engineering. Users are advised to avoid third-party app stores and unsolicited 'system update' messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.