"Đăng ký ngay" Báo cáo bán tuần Dự án Chất lượng Bậc A, Khám phá 1% Dự án xuất sắc nhất
API Tải ứng dụng RootData

Hackers forged Google Play Store pages to carry out cryptocurrency mining and wallet hijacking attacks targeting Brazilian users

Mar 22, 2026 18:49:52

Chia sẻ để

Hackers have launched Android malware attacks in Brazil by spoofing a phishing page that mimics the Google Play Store. Currently, all known victims are located in Brazil.

The attackers set up a phishing website that closely resembles Google Play, enticing users to download a fake application called "INSS Reembolso." Once installed, the application releases hidden malicious code in stages and loads it directly into memory, leaving no visible files on the device, which makes it highly stealthy. One of the core functions of the malware is cryptocurrency mining, with an embedded XMRig mining program compiled for ARM devices that silently connects to the attacker's controlled mining server in the background. The program monitors battery level, temperature, and device usage status, dynamically adjusting mining behavior to evade detection, and bypasses Android's background process management mechanism by looping silent audio files.

Some variants also include banking trojans that can overlay fake pages on the USDT transfer interface of Binance and Trust Wallet, silently replacing the recipient address. Additionally, the malware supports various remote control commands such as recording, screenshotting, keylogging, and remote locking of the device.

Tài chính và đầu tư gần đây

Xem thêm
$100M Apr 1, 2025
$1B Mar 20
-- Mar 20

Token được phát hành gần đây

Xem thêm
edgeX EDGE
Mar 19
Mar 18
Mar 18

𝕏 Sự quan tâm mới nhất

Xem thêm
Mar 21
Mar 21