logo

BeatBanker: A dual‑mode Android Trojan

ID: 86abba0c-def0-5596-aa96-5cd9eed054e7

STIX ID: report--86abba0c-def0-5596-aa96-5cd9eed054e7

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2026-03-10

Date Updated: 2026-04-29

Author: GReAT

...
...

BeatBanker is an Android malware campaign observed in Brazil that uses fake Google Play Store sites to trick victims into installing trojanized apps which then load payloads via an ELF/DEX loader. The threat combines an ARM XMRig cryptominer and a banking Trojan that abuses Accessibility and overlay capabilities to intercept and replace USDT transaction addresses, maintains persistence through near‑inaudible looped audio and foreground notifications, uses Firebase Cloud Messaging for C2, and recent variants deploy the BTMOB RAT; the report provides technical unpacking, a comprehensive command set, IoCs (domains and MD5 hashes), and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.