Phishing Campaign Delivers BeatBanker Trojan To Spread Cryptocurrency Miner and RAT

A recent phishing campaign has been targeting Brazilian users through a trojanized version of the Red Alert rocket warning app.

This malware, named BeatBanker, masquerades as a legitimate application, spreading via a fake Google Play Store page and targeting devices with both a cryptocurrency miner and a banking Trojan.

This multi-layered attack campaign exploits public safety concerns, especially during times of geopolitical tension, making it an effective tool for cybercriminals.

This article outlines the infection chain and how the malware operates to ensure long-term persistence and communication with mining pools.

Infection Chain and Malware Mechanism

The website hosts a Trojan posing as the “INSS Reembolso” app, which claims to be the official mobile portal for Brazil’s social security system, Instituto Nacional do Seguro Social (INSS).

The app lures users by offering access to government services such as tax records and retirement applications. Once the victim installs the trojanized app, the infection chain begins.

Once the app is running, it displays a fake Google Play Store interface that prompts the victim to “update” the app.

BeatBanker Trojan Spreads via Phishing (Source: securelist)
BeatBanker Trojan Spreads via Phishing (Source: securelist)

The update process downloads additional malicious payloads, including a cryptocurrency miner and a banking Trojan, both of which can run in the background and evade detection.

The cryptocurrency miner connects to a command-and-control (C2) server to mine cryptocurrency. At the same time, the banking Trojan targets financial transactions and banking applications like Binance and Trust Wallet.

Key Features and Capabilities

The BeatBanker malware leverages multiple tactics to maintain persistence and evade detection. It plays an almost inaudible audio file in the background, preventing the malware from being terminated easily.

BeatBanker Trojan Spreads via Phishing (Source: securelist)
BeatBanker Trojan Spreads via Phishing (Source: securelist)

Additionally, it checks the battery temperature and percentage, as well as user activity, to adjust its behavior accordingly. For example, it pauses cryptocurrency mining when the device is not charging or when the user is actively using it.

One of the most significant threats posed by BeatBanker is its banking Trojan functionality. The malware creates overlay screens that mimic legitimate cryptocurrency platforms like Binance and Trust Wallet.

When a victim attempts to make a transaction, the malware replaces the recipient’s address with the attacker’s, silently redirecting the funds to the attacker’s wallet.

It also monitors installed applications on the victim’s device, looking for financial apps, and exfiltrates browser history and stored credentials.

BeatBanker Trojan Spreads via Phishing (Source: securelist)
BeatBanker Trojan Spreads via Phishing (Source: securelist)

The BeatBanker campaign highlights the evolving sophistication of phishing attacks that use trojanized applications to target sensitive data, securelist including cryptocurrency credentials and banking information.

This attack exemplifies the dangers of fake apps that appear to be legitimate and exploit social engineering tactics to bypass security measures.

Organizations should enhance their mobile security practices and educate users to avoid installing apps from unofficial sources, especially when such apps pose as public safety tools.

Enhanced detection systems that monitor app behavior and network activity will be crucial for defending against these multi-layered attacks.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories