Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»New BeatBanker Android malware poses as Starlink app to hijack devices
    Cybersecurity

    New BeatBanker Android malware poses as Starlink app to hijack devices

    adminBy adminMarch 10, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    New BeatBanker Android malware poses as Starlink app to hijack devices
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New BeatBanker Android malware poses as Starlink app to hijack devices

    A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store.

    The malware combines banking trojan functions with Monero mining, and can steal credentials, as well as tamper with cryptocurrency transactions.

    Kaspersky researchers discovered BeatBanker in campaigns targeting users in Brazil. They also found that the most recent version of the malware deploys the commodity Android remote access trojan called BTMOB RAT, instead of the banking module.

    BTMOB RAT provides operators with full device control, keylogging, screen recording, camera access, GPS tracking, and credential-capture capabilities.

    Persistence via MP3

    BeatBanker is distributed as an APK file that uses native libraries to decrypt and load hidden DEX code directly into memory, for evasion.

    Before launching, it performs environment checks to ensure it’s not being analyzed. If passed, it displays a fake Play Store update screen to trick the victims into granting it permissions to install additional payloads.

    The fake update message
    The fake update message
    Source: Kaspersky

    To avoid triggering any alarms, BeatBanker delays malicious operations for a period after its installation.

    According to Kaspersky, the malware has an unusual method to maintain persistence, which consists of continuously playing a nearly inaudible 5-second recording of Chinese speech from an MP3 file named output8.mp3.

    “The KeepAliveServiceMediaPlayback component ensures continuous operation by initiating uninterrupted playback via MediaPlayer,” Kaspersky explains in a report today.

    “It keeps the service active in the foreground using a notification and loads a small, continuous audio file. This constant activity prevents the system from suspending or terminating the process due to inactivity.”

    Stealthy cryptocurrency mining

    BeatBanker uses a modified XMRig miner version 6.17.0, compiled for ARM devices, to mine Monero on Android devices. XMRig connects to attacker-controlled mining pools using encrypted TLS connections, and falls back to a proxy if the primary address fails.

    Miner deployment process
    Miner deployment process
    Source: Kaspersky

    The miner can be dynamically started or stopped based on device conditions, which the operators closely monitor to ensure optimal operation and maintain stealth.

    Using Firebase Cloud Messaging (FCM), the malware continuously sends the command-and-control (C2) server information about the device’s battery level and temperature, charging status, usage activity, and whether it has overheated.

    By stopping mining when the device is in use and by limiting its physical impact, the malware can remain hidden for a longer period, mining for cryptocurrency when conditions allow it.

    While Kaspersky observed all BeatBanker infections in Brazil, the malware could expand to other countries if proven effective, so vigilance and good security practices are recommended.

    Android users shouldn’t side-load APKs from outside the official Google Play store unless they trust the publisher/distributor, should review granted permissions for risky ones that aren’t relevant to the app’s functionality, and perform regular Play Protect scans.


    tines

    Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

    Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

    Android app BeatBanker Devices Hijack Malware poses Starlink
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous Article10 Best VPNs for USA in 2026
    Next Article Samsung’s Galaxy S26 hit with Play Protect issues even before they launch
    admin
    • Website

    Related Posts

    Wiz Joins Google Cloud as Landmark Acquisition Closes

    March 12, 2026

    Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown

    March 12, 2026

    Researchers uncover AI-powered vishing platform

    March 12, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    March’s free streaming lineup is so good it makes subscriptions feel optional

    March 12, 2026

    Wiz Joins Google Cloud as Landmark Acquisition Closes

    March 12, 2026

    How to watch Netflix in China

    March 12, 2026

    How To Prove PR Business Value With UTM Parameters & GA4

    March 12, 2026
    Categories
    • Blogging (37)
    • Cybersecurity (729)
    • Privacy & Online Earning (112)
    • SEO & Digital Marketing (460)
    • Tech Tools & Mobile / Apps (897)
    • WiFi / Internet & Networking (121)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    March’s free streaming lineup is so good it makes subscriptions feel optional

    March 12, 2026

    Wiz Joins Google Cloud as Landmark Acquisition Closes

    March 12, 2026

    How to watch Netflix in China

    March 12, 2026
    Most Popular
    • March’s free streaming lineup is so good it makes subscriptions feel optional
    • Wiz Joins Google Cloud as Landmark Acquisition Closes
    • How to watch Netflix in China
    • How To Prove PR Business Value With UTM Parameters & GA4
    • Adobe Photoshop: Photo Editor 1.3.0.2245 by Adobe
    • Which Samsung Galaxy S26 model should you buy?
    • Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown
    • Google expands Search Console branded queries filter to all eligible sites
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.