RewardDropMiner Android dropper activity delivering spyware and a Monero miner
Malware Activity
Summary
Hide ▲
Show ▼
Android dropper activity linked to RewardDropMiner is now delivering SMS stealers, spyware, and a remotely activatable Monero miner, expanding what a single installer can place on Android devices. The droppers are disguised as government and banking apps, with targeting concentrated in India and other parts of Asia. The modular design hides the payload behind a fake "Update" flow and lets operators swap components as defenses change.
Related Happenings
NGate malware trojanized HandyPay NFC-stealing variant
Malware Activity
H score34
First: 21.04.2026 12:00
Last: 21.04.2026 12:00
Sources 1
About this happening:
A new NGate variant is stealing NFC payment data from Android users in Brazil, raising the risk of unauthorized purchases and ATM cash withdrawals. The malware...
NGate malware trojanized HandyPay NFC-stealing variant
Malware ActivityAbout this happening: A new NGate variant is stealing NFC payment data from Android users in Brazil, raising the risk of unauthorized purchases and ATM cash withdrawals. The malware...
Perseus Android malware family actively distributed in the wild
Malware Activity
H score27
First: 19.03.2026 14:43
Last: 19.03.2026 14:43
Sources 1
About this happening:
The Perseus Android malware family is being actively distributed in the wild, putting infected devices at risk of device takeover and financial fraud. It spreads t...
Perseus Android malware family actively distributed in the wild
Malware ActivityAbout this happening: The Perseus Android malware family is being actively distributed in the wild, putting infected devices at risk of device takeover and financial fraud. It spreads t...
Perseus Android note-stealing and remote-control malware activity
Malware Activity
H score21
First: 19.03.2026 12:13
Last: 19.03.2026 12:13
Sources 1
About this happening:
The Perseus Android malware is now being used to inspect user notes for secrets, creating theft risk for passwords, recovery phrases, and financial data. It is als...
Perseus Android note-stealing and remote-control malware activity
Malware ActivityAbout this happening: The Perseus Android malware is now being used to inspect user notes for secrets, creating theft risk for passwords, recovery phrases, and financial data. It is als...
IPTV app lure campaign distributing Massiv Android banking malware
Campaign
H score25
First: 19.03.2026 12:13
Last: 19.03.2026 12:13
Sources 1
About this happening:
A recent IPTV app lure campaign is distributing Massiv Android banking malware, putting users who seek free or low-cost live sports broadcasts at risk of device compro...
IPTV app lure campaign distributing Massiv Android banking malware
CampaignAbout this happening: A recent IPTV app lure campaign is distributing Massiv Android banking malware, putting users who seek free or low-cost live sports broadcasts at risk of device compro...
BeatBanker Android phishing campaign targeting Brazilian users
Campaign
H score82
First: 12.03.2026 09:56
Last: 12.03.2026 09:56
Sources 1
About this happening:
A BeatBanker Android phishing campaign is targeting Brazilian users, creating a risk of device compromise and payment theft. The lure uses Google Play Store lookalike...
BeatBanker Android phishing campaign targeting Brazilian users
CampaignAbout this happening: A BeatBanker Android phishing campaign is targeting Brazilian users, creating a risk of device compromise and payment theft. The lure uses Google Play Store lookalike...
Timeline
-
01.09.2025 20:28 2 articles · 10mo ago
RewardDropMiner delivers spyware and a remotely activatable Monero miner
Initial DisclosureAndroid dropper activity targeting users in India and other parts of Asia is delivering spyware payloads and, in the RewardDropMiner variant, a Monero cryptocurrency miner that can be activated remotely. The same ecosystem includes droppers such as SecuriDropper, Zombinder, BrokewellDropper, HiddenCatDropper, and TiramisuDropper, which use fake government or banking app lures and a harmless-looking 'Update' screen to evade Google Play Protect and the targeted Pilot Program.
Show sources
- Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans — thehackernews.com — 01.09.2025 20:28
- Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans — thehackernews.com — 01.09.2025 20:28