#AndroidThreat
BeatBanker Trojan targets Brazil via phishing sites mimicking Google Play Store, deploying crypto miners and banking modules. Uses audio loops, Accessibility abuse, overlays, and Firebase for C2. #Brazil #AndroidThreat #CryptoMiner
BeatBanker: A dual‑mode Android Trojan
BeatBanker is an Android Trojan campaign that targets users in Brazil via phishing sites impersonating the Google Play Store to deliver a crypto miner and a banking module (recent samples drop the BTMOB RAT instead). It maintains persistence by looping an almost inaudible audio file, abuses Accessibility and overlay capabilities to intercept USDT transactions, and uses Firebase Cloud Messaging for command-and-control. #BeatBanker #BTMOB
www.hendryadrian.com
March 10, 2026 at 11:40 PM
Keenadu backdoor infiltrates Android firmware via malicious static libraries and OTA updates, enabling remote control, search hijacking, and stealthy ad interactions. DNS analysis revealed 29 IoCs tied to istaticfiles. #AndroidThreat #FirmwareAttack
DNS Analysis of the Keenadu Backdoor Network
Keenadu, a backdoor found in Android firmware, appears to have been introduced via a malicious static library linked to libandroid_runtime.so during firmware builds and, in other cases, pushed through OTA updates; it acts as a multistage loader enabling remote control, search hijacking, monetized app installs, and stealthy ad interactions. Extensive DNS and WHOIS analysis uncovered 29 primary IoCs (five subdomains, 20 domains, four IPs), dozens of associated email- and IP-connected domains, and additional weaponized IPs—highlighting infrastructure tied to istaticfiles[.]com. #Keenadu #istaticfiles
www.hendryadrian.com
April 15, 2026 at 2:15 AM
NoVoice malware infected over 2.3M Android devices via 50+ Google Play apps, using steganography to load a rootkit that steals WhatsApp encryption keys and clones accounts. #AndroidThreat #WhatsAppHack #GooglePlay
'NoVoice' Android malware on Google Play infected 2.3 million devices
NoVoice is a new Android threat found in over 50 Google Play apps with at least 2.3 million installs that uses steganography and a suite of exploits to obtain root and install a persistent rootkit. It injects into apps to steal sensitive data—most notably WhatsApp encryption keys and backups—allowing attackers to clone accounts; #NoVoice #WhatsApp
www.hendryadrian.com
April 1, 2026 at 8:40 PM
DroidLock Malware Warning: The New Android Threat That Locks Phones And Demands Cash #Cybersecurity #MalwareAlert #DroidLock #AndroidThreat
www.squaredtech.co/droidlock-ma...
DroidLock Malware Warning: The New Android Threat That Locks Phones And Demands Cash
DroidLock malware is a new Android threat that locks phones, steals data, and pressures victims for a ransom.
www.squaredtech.co
December 12, 2025 at 1:38 PM
3/3
✅ Avoid downloading APKs outside Google Play
✅ Keep Play Protect active
✅ Be cautious of unexpected wallet backup warnings

This threat may expand globally

#MalwareWarning #CryptoSecurity #AndroidThreat #crocodilus
March 31, 2025 at 9:48 AM