Hackers forged Google Play Store pages to carry out cryptocurrency mining and wallet hijacking attacks targeting Brazilian users
Hackers have launched Android malware attacks in Brazil by spoofing a phishing page that mimics the Google Play Store. Currently, all known victims are located in Brazil.
The attackers set up a phishing website that closely resembles Google Play, enticing users to download a fake application called "INSS Reembolso." Once installed, the application releases hidden malicious code in stages and loads it directly into memory, leaving no visible files on the device, which makes it highly stealthy. One of the core functions of the malware is cryptocurrency mining, with an embedded XMRig mining program compiled for ARM devices that silently connects to the attacker's controlled mining server in the background. The program monitors battery level, temperature, and device usage status, dynamically adjusting mining behavior to evade detection, and bypasses Android's background process management mechanism by looping silent audio files.
Some variants also include banking trojans that can overlay fake pages on the USDT transfer interface of Binance and Trust Wallet, silently replacing the recipient address. Additionally, the malware supports various remote control commands such as recording, screenshotting, keylogging, and remote locking of the device.
You may also like

Only 43% ROI on $1, why are 87% of Polymarket traders in the red?

After L2 Fraud, Ethereum Turns to ‘Economic Zone’ Self-Help

AI has simultaneously created a shortage and surplus of memory

How Can the Average Person Win in the 2026 AI Boom?

When Wall Street Meets Crypto, Here's Your "Stock Market Beginner & Advanced Guide"

StandX Introduces SIP1 and SIP2: Holding Subsidy Mechanism Launched, Reshaping On-Chain Trading and Reward Structure

Decoding Aave V4: A Shift from Product to "Banking"

Huobi HTX Releases "2026 Digital Asset Trends Whitepaper": Global Liquidity Reconfiguration, Defining the New Era of "On-Chain Finance"

PUMP Valuation Breakdown: Debunking On-Chain Data “Wash Trading” Narrative, Where Does the Real Discount Come From?

StandX launches SIP1 and SIP2: Position subsidy mechanism goes live, reshaping on-chain trading and revenue structure

Huobi HTX Releases the "2026 Digital Asset Trend White Paper": Global Liquidity Restructuring, Defining a New Sovereign Era of "On-Chain Finance"

DeFi Governance Revolution

Encrypted CEX is becoming a historical species

Who Pays for War? | Rewire News Morning Digest

Oil Price Surges Above $100, Yield Curve Inverts: U.S. Bonds Have Already Told the Market What Is Coming

Apple at 50: The Departure of Genius, the Permanence of the Machine

Disruption in the 13-week consecutive buying spree, What is the Strategy's Intent?

