Bitcoin Forum
August 25, 2026, 02:12:11 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: BeatBanker: An Android Trojan that operates in two modes  (Read 405 times)
fullfitlarry (OP)
Sr. Member
****
Offline

Activity: 462
Merit: 341


You Attract What You Are


View Profile
March 11, 2026, 09:20:27 AM
Merited by Mia Chloe (2), *Ace* (1)
 #1

Kaspersky recently identified a Android base malware that target Brazil again. The mode of infection is that it spreads thru phishing attacks disguised as a legitimate apps in Google Play Store.

For it's cryptocurrency capability,

  • It deploys a banker in addition to a cryptocurrency miner.
  • When the user attempts to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor’s transfer address.

So it will deploy as a miner and then track and monitor if you will make a USDT transaction and then becoming a copy and paste malware.



So far this is the domain that has been identified.

Code:
cupomgratisfood[.]shop
fud2026[.]com
accessor.fud2026[.]com
pool.fud2026[.]com
pool-proxy.fud2026[.]com
aptabase.fud2026[.]com
aptabase.khwdji319[.]xyz
btmob[.]xyz
bt-mob[.]net

https://securelist.com/beatbanker-miner-and-banker/119121/

So if someone from our Brazilian friends might have been reading this, so just be careful and download only from legitimate source.

Coloma612
Newbie
*
Offline

Activity: 20
Merit: 0


View Profile
March 12, 2026, 02:31:06 PM
 #2

When the user attempts to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor’s transfer address.

The "address replacement" trick is still one of the most effective ways to steal funds because even experienced users sometimes forget to double check every single character after pasting.

It is a good reminder that mobile security is often weaker than desktop. If you are using Trust Wallet or Binance on Android, always verify the address on a second device or at least check the last 5-10 digits before hitting send. Thanks for sharing the domains list.
fullfitlarry (OP)
Sr. Member
****
Offline

Activity: 462
Merit: 341


You Attract What You Are


View Profile
March 13, 2026, 09:26:08 AM
 #3

When the user attempts to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor’s transfer address.

The "address replacement" trick is still one of the most effective ways to steal funds because even experienced users sometimes forget to double check every single character after pasting.

It is a good reminder that mobile security is often weaker than desktop. If you are using Trust Wallet or Binance on Android, always verify the address on a second device or at least check the last 5-10 digits before hitting send. Thanks for sharing the domains list.

It is, that's why we really need to be very careful about sending someone our precious Bitcoin by checking the address first.

Or scan our hardware with the latest ant-virus as there could be malware hiding somewhere. Although not all can be tracked by anti-virus, at least this is a good practice. And not putting a lot of crypto in our pc or laptop, maybe just enough for us to used for daily like trading.

Yes, Android is not that good, but still if we practice safe hygiene, we could all be good.

Siros
Newbie
*
Offline

Activity: 22
Merit: 0


View Profile
March 13, 2026, 04:10:21 PM
 #4

So far this is the domain that has been identified.
Thanks for the warning and the domain list. These phishing attacks disguised as legitimate apps are the biggest threat for mobile wallet users right now. I always tell people that if they are doing large USDT transactions it is better to use a dedicated device or at least a hardware wallet that shows the address on a physical screen. Stay safe out there
Patikno
Sr. Member
****
Offline

Activity: 938
Merit: 323



View Profile WWW
March 13, 2026, 06:28:06 PM
 #5

The Beatbanker malware poses numerous Android security threats. It doesn't just steal information from Android devices, but it can also execute commands that harm users.

Some of the most dangerous things I have seen from the source the OP cited: include stealing authentication codes in Google Authenticator, bypassing security, accessing text from the clipboard, changing cryptocurrency addresses (especially USDT) when it detects a transaction, opening links in browsers, stealing information by activating a keylogger, and much more. It is truly terrifying; some of the things I have cited from the source are among the most dangerous. I think there is no way out for a user infected with this malware, except to perform a full wipe, and reset the device to its original factory firmware.

Fortunately, this malware can be avoided because it doesn't operate directly (requires user authorization), which means we must be vigilant in every activity we perform on our devices, and avoid being easily fooled by apps that look like official apps (like Google Play). The source also recommends: always using the official app for the device in question, checking and verifying its authenticity, then recommend to always checking every installed application, especially APKs from third parties or unknown sources (although, I don't recommend anyone using these types of applications).

By the way, I suspect this attack could spread to other countries (not just Brazil), so we need to remember this warning to avoid being fooled by such malware tricks. Essentially, most cyberattacks require our authorization to provide a loophole, so don't carelessly grant any authorization, especially to install applications from unknown sources.

There are so many things that can threaten our devices in this online world. If you are the type of person who likes to surf and experiment with many things, then use a device that doesn't contain important information, or sensitive data (including cryptocurrency assets). Essentially, try to separate important devices from those you can afford to expose to threats. Personally, I have a dedicated device that I frequently use to experiment with various things, including dangerous ones, and I deliberately don't store any important information on it. So, if something happens to my device, I won't lose anything valuable. I hope my advice helps you.

█████████████████████████████
█████████████████████████
█████████████████████████
███████████▀▄▀███████████
██▄▀▀▀██▀▄███▄▀██▀▀▀████
██▌▐███▄▄█████▀███████▐██
████████████████████████
███▌▐████████████████▐███
████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████████
 rizzy 
██████
██
██
██
██
██
██
██
██
██
██
██
██████
█▌█▌█▌████
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌██
█▌█▌█▌████
████████████

 
████████████
██████████████████████████████████████████████████████████████████
 
THE HOME OF THE
   MOST REWARDING   
GAMING EXPERIENCE
██████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████
100%DEPOSIT
MATCH
+ 100 FREE SPINS
██████████████████████████████████████████████████████████████████
████████████

 
████████████
████▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
██▐█▐█▐█
████▐█▐█▐█
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
Mia Chloe
Legendary
*
Offline

Activity: 1176
Merit: 2284


Contact me for your designs...


View Profile
March 13, 2026, 10:29:25 PM
 #6

The Beatbanker malware poses numerous Android security threats. It doesn't just steal information from Android devices, but it can also execute commands that harm users.
Security and privacy is actually becoming more and more difficult every day that passes. We barely have safe routes these days and sadly over 50% of these threats of not more are coming from the internet and you literally can't do almost anything without going online which can complicate things for you.

~snip
Is this only affecting people from Brazil or everyone that falls for it, plus how feasible is the functionality of the malware on bitcoin only wallets I'm asking because you didn't mention any so far.

DubemIfedigbo001
Hero Member
*****
Offline

Activity: 1134
Merit: 716


Let love lead


View Profile WWW
March 13, 2026, 10:49:36 PM
 #7

  • When the user attempts to make a USDT transaction, BeatBanker creates overlay pages for Binance and Trust Wallet, covertly replacing the destination address with the threat actor’s transfer address.
Maybe, Just maybe those that used the "Withdraw again" features on Binance would be somehow safe from it's manipulations since the app would put in the previously used address automatically for you and I doubt the overlay page would be able to retrieve your withdrawal history from Binance database, so it may only be affecting those who copy and paste addresses in withdrawal pages,. Or maybe when you send to a new address.

If you are still cautious and not do Ctrl+C and Ctrl+V mindlessly but check your addresses carefully with the source, you would notice the disparity between the two addresses soon enough.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
fullfitlarry (OP)
Sr. Member
****
Offline

Activity: 462
Merit: 341


You Attract What You Are


View Profile
March 14, 2026, 01:07:28 AM
 #8

The Beatbanker malware poses numerous Android security threats. It doesn't just steal information from Android devices, but it can also execute commands that harm users.
Security and privacy is actually becoming more and more difficult every day that passes. We barely have safe routes these days and sadly over 50% of these threats of not more are coming from the internet and you literally can't do almost anything without going online which can complicate things for you.

~snip
Is this only affecting people from Brazil or everyone that falls for it, plus how feasible is the functionality of the malware on bitcoin only wallets I'm asking because you didn't mention any so far.

Yes, initially it was affecting Brazilian users. But we all know that this is just the beginning.



From what I observed, usually this is how they will moved, Banking system->cryptocurrency. So they will just evolved and could released the next iteration of this malware that will include everything, from USDT to Bitcoin and any other altcoin addresses and that is very dangerous to all of us.

Nathrixxx
Sr. Member
****
Offline

Activity: 630
Merit: 298


Bitz.io Best Bitcoin and Crypto Casino


View Profile
March 14, 2026, 03:17:58 AM
 #9

We can neglect information source and that is one of the reason why you this forum has been the best platform to discuss about cryptocurrency, not only that, also share more information about what is expected of everyone to know or do to prevent our asset from being taken by others, scam attends like this must be exposed and others have to know what is happening by being informed of their tactics.

█ 
███████▄▄███▄███▄
███▄▄████████▌██
▄█████████████▐██▌
██▄███████████▌█▌
███████▀██████▐▌█
██████████████▌▌▐
████████▄███████▐▐
█████████████████
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io█ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀██
███████████████▐▌
███████████████▐▌
███▄▄████▄▄▄██▄▄
▄█████████████████████▄
████████████████████
██
█████████████████████
▀██
█████████████████████▀
▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
███████████████▄
▄███████████████████▄
▄██████████████
██████▄
▄██████████████████████
████████████████████████
███████████████████████
██████████████████████
████████████████████████
▀█████████████████████▀
███████████████████▀
███████████████▀
▀▀███████▀▀
HIGH
ODDS
 
█████████   ██

......PLAY NOW......

██   █████████
█ 
Somegory
Full Member
***
Offline

Activity: 392
Merit: 201



View Profile
March 14, 2026, 07:30:05 AM
 #10

So far this is the domain that has been identified.
Thanks for the warning and the domain list. These phishing attacks disguised as legitimate apps are the biggest threat for mobile wallet users right now. I always tell people that if they are doing large USDT transactions it is better to use a dedicated device or at least a hardware wallet that shows the address on a physical screen. Stay safe out there

With hardware wallet you don't have to copy paste any address, all you have to do is scan the QR code and you will get the correct address which adds more to the security, this is goodbye to fake address and others.

I don't know why people are still using mobile wallets with all the troubles going around android devices this days, too many vulnerability are showing up with android OS and chips, thanks to those detecting them and bring it to light, if not? Millions of people will lose their coin.

Hardware wallets will fix 90% of the problems affecting crypto investors this days, the remaining 10% problem is users keeping their recovery seed safe, in a offline way, the only way they can lose here is exposing the seeds themselves.

Rikafip
Legendary
*
Offline

Activity: 2590
Merit: 8251



View Profile
March 14, 2026, 08:50:32 AM
 #11

I don't know why people are still using mobile wallets with all the troubles going around android devices this days
Because some people still need a hot wallet for an easy and convenient access to their crypto.

Trick is not to store large amounts on them, but only a few hundreds of dollars worth of crypto so if something happens, you won't lose much. At least that's what I am doing.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
joniboini
Legendary
*
Offline

Activity: 3024
Merit: 1919



View Profile WWW
March 14, 2026, 05:20:45 PM
 #12

With news like this, I wonder how much Google actually filters. On some reports, we heard that Google or Apple removes thousands (or millions) of malware/phishing apps from their store, yet we keep seeing new exploited apps like this once in a while. There must be some trigger before it goes to manual verification ( I hope), so I guess a lack of reports probably helps malware stay alive to some extent.

Still, I find it hard to believe apps with thousands of downloads failed to get verified correctly. It doesn't help that some developers are targeted, too.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
sunsilk
Hero Member
*****
Offline

Activity: 3752
Merit: 656



View Profile
March 14, 2026, 11:50:57 PM
 #13

We can neglect information source and that is one of the reason why you this forum has been the best platform to discuss about cryptocurrency, not only that, also share more information about what is expected of everyone to know or do to prevent our asset from being taken by others, scam attends like this must be exposed and others have to know what is happening by being informed of their tactics.
The problem is that the specific target users, many are not here and that's what makes them so vulnerable.

When they're not aware of it, that makes them the easiest target from these malware.

So awareness and being researchful saves us from these malware even if we're not the target of it. We have to be careful of it and modify our actions from the wallets we download or use with our mobiles.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
Emjay24
Sr. Member
****
Offline

Activity: 588
Merit: 320



View Profile
March 15, 2026, 05:01:10 AM
 #14

We can neglect information source and that is one of the reason why you this forum has been the best platform to discuss about cryptocurrency, not only that, also share more information about what is expected of everyone to know or do to prevent our asset from being taken by others, scam attends like this must be exposed and others have to know what is happening by being informed of their tactics.
The problem is that the specific target users, many are not here and that's what makes them so vulnerable.

When they're not aware of it, that makes them the easiest target from these malware.

So awareness and being researchful saves us from these malware even if we're not the target of it. We have to be careful of it and modify our actions from the wallets we download or use with our mobiles.
Many of them are not even tech savvy and a good number of them are old guys who would definitely not have the strength for continuous research on their crypto security updates which makes them vulnerable.

Again there is information overload on the internet and you may not know the sources they get theirs, it may be the wrong one and such practices would lead them to wrong practices.

NotATether
Legendary
*
Offline

Activity: 2436
Merit: 10174


┻┻ ︵㇏(°□°㇏)


View Profile WWW
March 15, 2026, 06:47:29 AM
 #15

If it's disguised as apps on Google Play, why aren't they simply reported so that they are taken down? Usually what happens next is that the Google Play developer account gets closed.

It is quite simple to fake, e.g. a physical device in a device lab for this purpose.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
rdluffy
Legendary
*
Online Online

Activity: 3066
Merit: 2064



View Profile WWW
March 15, 2026, 12:32:03 PM
 #16

I think it’s the same malicious app that was posted here: https://bitcointalk.org/index.php?topic=5577214.0

I use iOS here, but several people I know who use Android have APKs installed from outside the official Play Store, whether it’s a music app, video app, etc
I always remind them that it’s extremely dangerous to download a malicious app like this
Next time, I’ll warn them about this latest scam

For crypto users, it’s even more dangerous, but even someone without crypto can still lose money and data

▄▄████████████████████▄▄
████████████████████████
██████████████████████████
██████████████████████████
███▄▄▀▀▀▀▀▀▀▀▀▀▄▄██
██████████▐████▐██████
███▀██████▀▀████▀▀███████
██████████████████████
████▄▄██▄▄▄▄███▄▄▄███████
██████▀▀▀▀▀▀▀▀▀▀▀▀██████
██████████████████████████

████████████████████████
▀▀████████████████████▀▀

..1win..
█████████████████████████
█████████████████████████
████████████▀░░░▀▀▀▀█████
█████████▀▀▀█▄░░░░░░░████
████▀▀░░░░░░░█▄░▄░░░▐████
████▌░░░░▄░░░▐████░░▐███
█████░░░▄██▄░░██▀░░░█████
█████▌░░▀██▀░░▐▌░░░▐█████
██████░░░░▀░░░░█░░░▐█████
██████▌░░░░░░░░▐█▄▄██████
███████▄░░▄▄▄████████████
█████████████████████████
█████████████████████████

..POKER..
█████████████████████████
█████████████████████████
███████████▀▀▀███████████
███████▀▀░░▄▄▄░░▀▀███████
██████▄░░░░███░░░░▄██████
█████░▀▀█▄▄░░░▄▄█▀▀░█████
█████░██░░▀▀█▀▀░░██░█████
█████░░░░░░░█░██░▄▄░█████
█████▄░░░▄▄░█░▄▄░▀▀▄█████
███████▄▄▀▀░█░▀▀▄▄██████
███████████▄█▄███████████
█████████████████████████
█████████████████████████

..GAMES..
█████████████████████████
█████████████████████████
████████▀▀░░░░░▀▀████████
██████░░▄██▄░▄██▄░░██████
█████░░████▀░▀████░░█████
████░░░░▀▀░░░░░▀▀░░░░████
████░░▄██░░░░░░░██▄░░████
████░░████░░░░░████░░████
█████░░▀▀░▄███▄░▀▀░░████
██████░░░░▀███▀░░░░██████
████████▄▄░░░░░▄▄████████
█████████████████████████
█████████████████████████
Mitchell
Global Moderator
Legendary
*
Offline

Activity: 4746
Merit: 3259


Verified awesomeness ✔


View Profile
March 15, 2026, 04:44:52 PM
Merited by TypoTonic (1)
 #17

I think it’s the same malicious app that was posted here: https://bitcointalk.org/index.php?topic=5577214.0
This topic was the first one, so the other one was moved to Trashcan. Honestly, I might start a [General] thread for all these malware warnings, since a big part of B&H seems to be that these days.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
sunsilk
Hero Member
*****
Offline

Activity: 3752
Merit: 656



View Profile
March 15, 2026, 09:41:19 PM
 #18

The problem is that the specific target users, many are not here and that's what makes them so vulnerable.

When they're not aware of it, that makes them the easiest target from these malware.

So awareness and being researchful saves us from these malware even if we're not the target of it. We have to be careful of it and modify our actions from the wallets we download or use with our mobiles.
Many of them are not even tech savvy and a good number of them are old guys who would definitely not have the strength for continuous research on their crypto security updates which makes them vulnerable.

Again there is information overload on the internet and you may not know the sources they get theirs, it may be the wrong one and such practices would lead them to wrong practices.
That's the problem that they have to face and we shouldn't be problematic about them anymore if they don't do their research.

Because as you've said, we've got information overload in the web and it's only needed to be searched and it will show up.

Maybe they'll also get through a hardship of learning it once and then will follow it then by next when they don't want to fall again to these malware.

This topic was the first one, so the other one was moved to Trashcan. Honestly, I might start a [General] thread for all these malware warnings, since a big part of B&H seems to be that these days.
It's a good idea or maybe a child/sub board here in B&H for malware.

 
 RAZED  
| 
 100% 
WELCOME
BONUS
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
| 
 NO 
KYC
| 
  RAZE THE LIMITS    PLAY NOW     
*Ace*
Hero Member
*****
Offline

Activity: 518
Merit: 945



View Profile
March 22, 2026, 10:04:50 PM
 #19

First of all, thank you so much for alerting everyone with this dedicated thread. I’d say it’s very useful.
I wanted to ask you: do you happen to know if the attack is limited to Brazil, or are there already cases in other countries as well?
Unfortunately, there are quite a few malicious people out there, and we must always be on our guard

promise444c5
Legendary
*
Offline

Activity: 1120
Merit: 1102


All things are numbers


View Profile WWW
March 23, 2026, 11:16:54 PM
 #20

I wanted to ask you: do you happen to know if the attack is limited to Brazil, or are there already cases in other countries as well?
Brazil is specifically the primary target only because the fake Google Play site, cupomgratisfood[.]shop hosted the INSS Reembolso app which contains malware used for the attack.. The app itself was used as disguised to make visitors  think they are downloading a similar app to  Meu INSS – Central de Serviços app which is the real app on Play Store.

It seems victims were trick to believing they can get some kind of reimbursement , read that from this article .. used translator btw, not sure if you speak Portuguese but you can get the full gist  there..

The point is that the social engineering & the some of the exploit behind it will likely targets only Brazillians  but the malware itself can target anyone , they just have to create other generic apps with different logics and modifications.

Have you seen this though : https://bitcointalk.org/index.php?topic=5577850.0

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!