A new Android malware called BeatBanker is being distributed through fraudulent websites that impersonate the official Google Play Store.
Key Features and Behavior
The malware is primarily targeting users in Brazil by masquerading as a legitimate Starlink application.
- Dual-Threat Capabilities: BeatBanker combines banking trojan functions with a cryptocurrency miner that harvests Monero (XMR).
- Device Hijacking: Recent variants have been observed deploying the BTMOB RAT (Remote Access Trojan), granting attackers full control over the device, including keylogging, screen recording, and camera access.
- Persistence via Audio: To prevent the Android OS from terminating its background process, the malware continuously plays a nearly inaudible 5-second audio loop.
- Evasion Techniques: It uses native libraries to decrypt and load malicious code directly into memory and performs environment checks to detect if it is being analyzed by security researchers.
- Stealthy Mining: The malware monitors device conditions such as battery level, temperature, and charging status via Firebase Cloud Messaging (FCM) to stop mining when the user is active, helping it remain undetected for longer.
Safety Recommendations
- Official Sources Only: Only download the Starlink app from the official Google Play Store.
- Check Permissions: Be wary of apps requesting REQUEST_INSTALL_PACKAGES or Accessibility Services if they are not essential for the app’s function.
- Verify Domains: Avoid downloading APK files from unofficial domains like
cupomgratisfood[.]shop.