Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cryptocurrency-platform-riskidentity-impersonation-fraudphishing-campaign-intelligenceremote-access-implant

Scams and Malware Abusing Google Branding to Steal Cryptocurrency

Updated 3mo agoFirst seen Mar 10, 20262 sources

Security researchers reported multiple campaigns abusing Google branding to drive crypto theft. Malwarebytes identified a polished fraudulent “presale” site promoting a fake token called “Google Coin” and embedding a chatbot that impersonates Google Gemini; the bot delivers a scripted investment pitch, cites specific token pricing and a “2026 roadmap,” and steers victims toward sending irreversible cryptocurrency payments while avoiding verifiable corporate, regulatory, or registration details.

Separately, Kaspersky’s Securelist detailed BeatBanker, an Android malware campaign targeting Brazil that spreads via phishing to a website masquerading as the Google Play Store (e.g., cupomgratisfood[.]shop) and distributing trojanized APKs such as a fake “INSS Reembolso” app. The malware combines a cryptominer with a banking Trojan capable of device hijacking and screen overlays, including swapping destination addresses during USDT transactions in apps like Binance and Trust Wallet; newer samples reportedly replaced the banking module with BTMOB RAT while retaining the broader infection chain and persistence techniques (including looping near-inaudible audio to resist termination).

Share:
Scams and Malware Abusing Google Branding to Steal Cryptocurrency
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 10, 20263mo ago

Malwarebytes reports fake Gemini chatbot promoting 'Google Coin' scam

Malwarebytes researchers reported a cryptocurrency scam that impersonates Google branding and a Gemini-like AI assistant to market a fake token called “Google Coin.” The fraudulent presale site used a scripted chatbot, false trust logos, and directed victims to a fake wallet dashboard and Bitcoin payment request.

Newer BeatBanker variants switch from banking Trojan to BTMOB RAT

Kaspersky said newer BeatBanker samples retained the miner and persistence mechanisms but replaced the earlier banking module with the BTMOB RAT, a MaaS remote administration tool associated with the CraxsRAT/CypherRAT/SpySolr ecosystem. The report also detailed extensive remote-control capabilities including screen capture, keylogging, SMS sending, device locking or wiping, and audio recording.

BeatBanker Android campaign targets Brazilian users via fake Play Store site

Kaspersky reported an Android malware campaign in Brazil in which victims were lured through phishing pages mimicking the Google Play Store to install trojanized apps such as “INSS Reembolso.” The malware used packed loaders, in-memory DEX execution, persistence tricks, and deployed a Monero miner while earlier waves also included a banking Trojan.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Affected products
7 linked
MalwarebytesAndroidWhatsappBraveFirefoxTrust WalletOpera
Organizations
13 linked
BinanceGoogleMalwarebytesSquarespaceOpenaiCoinbaseSpaceXKasperskyCYFIRMAGitHubTelegramTrust Walletipapi.is
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Scams and Malware Abusing Google Branding to Steal Cryptocurrency | Mallory