New BeatBanker Android malware poses as Starlink app to hijack devices
ID: 0332981b-5047-5bcb-9890-63a7132712b9
STIX ID: report--0332981b-5047-5bcb-9890-63a7132712b9
Feed Name: Bleeping Computer
A Kaspersky analysis details BeatBanker, an Android malware campaign in Brazil that masquerades as a Starlink/Play Store app to trick users into installing an APK which loads hidden DEX code; it combines banking-trojan capabilities and Monero mining (modified XMRig) and recent samples deploy the BTMOB RAT for full device takeover, using unusual persistence via continuous near-inaudible MP3 playback and stealth techniques (delayed actions, environment checks, FCM-based telemetry) to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
