A new and particularly dangerous malware for Android, known as BeatBanker, has begun to attract the attention of cybersecurity experts. The malware is distributed via deceptive websites that mimic the official Google app store and falsely presents itself as an app for SpaceX's Starlink satellite internet service.
According to Kaspersky, the threat combines banking trojan capabilities with illegal cryptocurrency mining, creating a multifunctional tool for cybercriminals. Through BeatBanker, attackers can steal user credentials, monitor financial transactions, and even interfere with digital asset transfers.
Targeted attacks and campaign spread
The first campaigns, which security analysts have identified, primarily targeted users in Brazil. However, experts warn that the geographical spread of such malware could be rapid, especially if it proves effective in deceiving users.
See also: APT28 spies on the Ukrainian military with BEARDSHELL and COVENANT

The distribution method relies on fake websites that mimic the design and functionality of the Google Play Store. Through these pages, users are invited to download an APK installation file that appears to be the official Starlink app, while in reality it contains the malicious code.
In newer versions of the malware, researchers noticed that instead of the classic banking module, BeatBanker installs the BTMOB RAT, a powerful remote access trojan for Android.
Full device control via BTMOB RAT
The BTMOB RAT gives attackers extensive control over the infected device. Among other things, it can perform keylogging , real-time screen recording , and access the smartphone's camera
At the same time, the malware can collect geolocation data via GPS, record device usage activity , and extract login credentials from applications or services.
The combination of these capabilities allows attackers to monitor almost every user action, turning the smartphone into a spying tool.
Mechanisms of concealment and evasion of detection
BeatBanker is distributed as an APK file that uses special libraries to decrypt and load hidden DEX code directly into the device's memory. This method avoids detection by many security tools.
See also: Malicious npm package impersonates OpenClaw and deploys RAT
Before activating its malicious functions, the malware performs checks on the device environment to determine if it is in an analysis or sandbox environment. If it passes the checks, it displays a fake Play Store update screen to convince the victim to grant additional permissions.
Additionally, it delays the execution of malicious functions for a period of time after installation, reducing the likelihood of raising suspicion.

Unusual persistence technique via MP3 file
One of the strangest features of BeatBanker is the method it uses to stay active on the system. According to Kaspersky's analysis, the malware continuously plays a nearly silent MP3 audio file of Chinese speech lasting about five seconds.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The file, named output8.mp3, is executed through a playback mechanism that keeps the application active in the foreground. This way, the Android operating system does not terminate the process due to inactivity.
This technique is considered particularly ingenious, as it exploits the way Android manages applications to keep the malware active without being easily detected.
Hidden cryptocurrency mining on infected devices
In addition to stealing data, BeatBanker uses infected devices to mine the cryptocurrency Monero. For this purpose, it leverages a modified version of the popular mining software XMRig.
This particular version has been adapted for ARM processors, allowing execution on Android devices. The miner connects to mining pools controlled by the attackers, using encrypted TLS connections.
At the same time, the malware continuously monitors the device's status, including battery level, temperature, and usage activity. This data is sent to command and control servers via Firebase Cloud Messaging.
Based on this information, attackers enable or disable mining to avoid overheating or excessive battery consumption, thus keeping the activity hidden.
See also: Hacker exploits .arpa domain to bypass phishing detection

How Android users can protect themselves
Experts emphasize that the best defense against such threats is careful user behavior. Application installation should be done exclusively from the official Google store, while APK files from unknown sources should be avoided.
Additionally, it is important for users to check the permissions each app requests and decline any that are not relevant to its functionality. Enabling Play Protect and running regular security scans can also help detect malware early.
As threats to mobile devices become increasingly sophisticated, user awareness and vigilance remain critical factors for protecting personal data.
Source: www.bleepingcomputer.com
