logo

More Than a Miner: The Evasive MiningDropper Framework Hijacking Android Worldwide

ID: 598bf0ee-9225-544f-b1f0-e46bcaf7424d

STIX ID: report--598bf0ee-9225-544f-b1f0-e46bcaf7424d

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-20

Date Updated: 2026-05-05

Author: Ddos

...
...

A CRIL investigative report describes "MiningDropper", a sophisticated, modular Android malware distribution framework that uses XOR-based native obfuscation, AES-encrypted payload staging, dynamic DEX loading, memory-only deobfuscation, and anti-emulation to evade analysis. The framework can deliver a range of monetization payloads — from silent crypto miners to infostealers and the BTMOB RAT — and has been observed in active, regionally tailored campaigns targeting India and multiple global regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.