CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

BeatBanker Android malware targets users with Starlink app disguise

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new Android malware named BeatBanker impersonates a Starlink app to hijack devices. It combines banking trojan functions with Monero mining, stealing credentials and tampering with cryptocurrency transactions. The malware is distributed via fake Google Play Store websites and uses sophisticated evasion techniques, including persistence via an inaudible MP3 file and dynamic mining operations. Kaspersky researchers discovered the malware targeting users in Brazil, with potential for expansion to other regions.

Timeline

  1. 10.03.2026 23:27 1 articles · 14h ago

    BeatBanker Android malware discovered targeting Brazilian users

    Kaspersky researchers discovered the BeatBanker Android malware, which impersonates a Starlink app to hijack devices. The malware combines banking trojan functions with Monero mining and uses sophisticated evasion techniques, including persistence via an inaudible MP3 file and dynamic mining operations. The malware deploys the BTMOB RAT, providing operators with extensive control over infected devices. All observed infections are currently targeting users in Brazil.

    Show sources

Information Snippets