Kaspersky recently identified a Android base malware that target Brazil again. The mode of infection is that it spreads thru phishing attacks disguised as a legitimate apps in Google Play Store.
For it's cryptocurrency capability,
- It deploys a banker in addition to a cryptocurrency miner.
- When the user attempts to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor’s transfer address.
So it will deploy as a miner and then track and monitor if you will make a USDT transaction and then becoming a copy and paste malware.

So far this is the domain that has been identified.
cupomgratisfood[.]shop
fud2026[.]com
accessor.fud2026[.]com
pool.fud2026[.]com
pool-proxy.fud2026[.]com
aptabase.fud2026[.]com
aptabase.khwdji319[.]xyz
btmob[.]xyz
bt-mob[.]net
https://securelist.com/beatbanker-miner-and-banker/119121/So if someone from our Brazilian friends might have been reading this, so just be careful and download only from legitimate source.