A newly discovered Android malware campaign has emerged, targeting Hindi-speaking users in India with a unique dual-threat attack.
Uncovered by McAfee’s Mobile Research Team, the malware is being distributed through fake banking websites that impersonate trusted Indian financial institutions, including SBI Card, Axis Bank, and IndusInd Bank.
The campaign employs convincing phishing tactics, using logos and content copied from official sites to lure victims into installing a malicious Android app.

Dual-Purpose Malware: Data Theft Meets Cryptomining
What sets this campaign apart is its ability to steal sensitive financial information while silently hijacking infected devices’ resources to mine Monero cryptocurrency.
The spoofed apps demand users “update” their app, masquerading as a legitimate Google Play update screen.
Once installed, the fake app appears to function like a genuine banking service, prompting users to enter confidential details such as their name, card number, CVV, and expiration date.
This harvested information is swiftly transmitted to the attackers’ command-and-control server, putting users at serious risk of fraud. Behind the scenes, the app employs a complex, multi-stage loading process to avoid detection.
The malicious APK initially contains an encrypted file that, when decrypted, loads further encrypted code in memory. This staged approach makes detection by regular security tools much harder, as no harmful code is exposed until runtime.
A more insidious aspect of this campaign is its use of Firebase Cloud Messaging (FCM). By abusing FCM’s push notification system, attackers can remotely trigger a hidden cryptocurrency mining process on infected devices.
The malware downloads and executes an encrypted native binary, effectively an XMRig miner, which utilizes the device’s CPU to mine Monero in the background.
Monero is favored by cybercriminals for its privacy features and can be efficiently mined on mobile devices due to its CPU-optimized RandomX algorithm.
Stealth and Sophistication Raise the Bar on Mobile Threats
The campaign is primarily confined to India, likely because it features Hindi-language phishing pages and leverages genuine assets from Indian banks.
By spreading via rapidly created phishing sites with authentic-looking web resources, the attackers increase the likelihood of success while avoiding detection by conventional anti-malware solutions.
McAfee has reported the malicious apps to Google, leading to the suspension of the associated FCM accounts. The company’s security solutions now detect and block these high-risk threats.

Protecting Yourself: Simple Steps Can Make a Difference
Users are advised to download apps only from trusted sources like Google Play, be cautious of unsolicited links, and refrain from sharing sensitive financial information with unfamiliar apps.
Enabling security solutions that screen for malicious apps and phishing sites provides an essential last line of defense against evolving mobile threats like this.
With cybercriminals advancing new tactics that combine financial scams and cryptomining, vigilance and robust security remain crucial for mobile users, especially in regions most frequently targeted by such attacks.

Indicators of Compromise (IOCs)
| Type | Value | Description |
| APK | 2c1025c92925fec9c500e4bf7b4e9580f9342d44e21a34a44c1bce435353216c | SBI Credit Card |
| APK | b01185e1fba96209c01f00728f6265414dfca58c92a66c3b4065a344f72768ce | ICICI Credit Card |
| APK | 80c6435f859468e660a92fc44a2cd80c059c05801dae38b2478c5874429f12a0 | Axis Credit Card |
| APK | 59c6a0431d25be7e952fcfb8bd00d3815d8b5341c4b4de54d8288149090dcd74 | IndusInd Credit Card |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates