Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceremote-access-implantcredential-stealer-activityloader-delivery-mechanism

BeatBanker Android Malware Campaign Impersonating Starlink and Government Apps

Updated 3mo agoFirst seen Mar 11, 20267 sources

Kaspersky reported a new Android malware campaign dubbed BeatBanker targeting users in Brazil, distributed via phishing sites that closely mimic the Google Play Store and lure victims into installing trojanized APKs posing as legitimate apps such as Starlink and the Brazilian government services app INSS Reembolso. The infection chain is staged to reduce suspicion: an initial decoy app presents a fake in-app “update” flow that prompts users to grant permission to install additional apps/modules, after which the malware pulls down further payloads and requests expanded privileges.

Technical reporting indicates BeatBanker blends banking trojan capabilities with cryptomining (including a modified XMRig), and newer variants may deploy the commodity Android RAT BTMOB in place of the banking module, enabling broad device takeover (e.g., keylogging, screen recording, camera access, GPS tracking, and credential capture). The malware uses evasion techniques such as decrypting and loading hidden DEX code in-memory, performing anti-analysis environment checks, delaying malicious actions post-install, and maintaining persistence by continuously playing a near-inaudible MP3 (output8.mp3) to keep a foreground service alive and reduce the likelihood of the process being suspended by Android power management.

Share:
BeatBanker Android Malware Campaign Impersonating Starlink and Government Apps
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 11, 20263mo ago

Kaspersky publicly discloses BeatBanker and BTMOB campaign details

Kaspersky published its findings on the BeatBanker Android malware campaign, describing its infection chain, Firebase Cloud Messaging-based command-and-control, mining behavior, and BTMOB-linked variants. The company warned the activity was currently concentrated in Brazil but could expand further.

Newer BeatBanker variants begin deploying BTMOB RAT

Kaspersky reported that more recent variants replaced or supplemented the banking module with the BTMOB remote-access trojan. This expanded the campaign from financial theft and mining to full device surveillance and control, including keylogging, screen recording, camera access, and geolocation tracking.

Mar 10, 20263mo ago

Researchers identify stealth persistence and evasion techniques in BeatBanker

Analysis showed BeatBanker decrypts and loads hidden code in memory, performs anti-analysis checks, and uses fake Play Store update prompts to gain permissions and fetch additional payloads. It also maintains persistence by running a foreground service that plays a nearly inaudible looping audio file and can throttle mining based on device conditions.

BeatBanker uses banking theft, crypto hijacking, and Monero mining

Researchers found the malware combines banking-trojan functions with cryptocurrency theft and covert Monero mining on infected Android devices. It steals credentials, abuses accessibility and overlays, and can tamper with wallet transactions by replacing recipient addresses.

BeatBanker campaign targets Android users in Brazil via fake app sites

Kaspersky observed a newly identified Android malware campaign in Brazil distributing trojanized apps through phishing pages that mimic the Google Play Store. The lures impersonated services including Starlink and the Brazilian government-themed "INSS Reembolso" app.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Threat actors
1 linked
Affected products
11 linked
AndroidTrust WalletMagicosSamsung Internet BrowserMiuiColorosBrave BrowserOpera BrowserOne UiOxygenosFirebase Cloud Messaging
Organizations
23 linked
KasperskyGoogleBinanceMozillaCybleExpediaSamsung ElectronicsBrave SoftwareXiaomiZimperiumCYFIRMAOperaDuckduckgoTelegramOneplusOppoTrust WalletSicrediCertosCorreiosHonor Device Co., Ltd.StarlinkBleepingComputer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.