logo

New BeatBanker Android malware poses as Starlink app to hijack devices

ID: 0332981b-5047-5bcb-9890-63a7132712b9

STIX ID: report--0332981b-5047-5bcb-9890-63a7132712b9

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-03-10

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

A Kaspersky analysis details BeatBanker, an Android malware campaign in Brazil that masquerades as a Starlink/Play Store app to trick users into installing an APK which loads hidden DEX code; it combines banking-trojan capabilities and Monero mining (modified XMRig) and recent samples deploy the BTMOB RAT for full device takeover, using unusual persistence via continuous near-inaudible MP3 playback and stealth techniques (delayed actions, environment checks, FCM-based telemetry) to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.