MiningDropper (BeatBanker) modular Android payload framework with encrypted staging
Technical Analysis
Summary
Hide ▲
Show ▼
MiningDropper (BeatBanker) now stands out as a layered modular Android malware framework that can reuse one delivery chain across hundreds of samples, making static analysis and blocklisting harder. The framework swaps final payloads as needed, including cryptomining, information theft, remote access, and banking malware. Its use of XOR-based native obfuscation, AES-encrypted payload staging, dynamic DEX loading, and anti-emulation raises the cost of inspection and detection. The result is a flexible Android infection platform that can be repurposed quickly for different monetization goals.
Related Happenings
CrashStealer analysis of client-side AES-GCM encryption and anti-analysis techniques
Technical Analysis
H score28
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
Researchers published a technical analysis of CrashStealer that adds reusable detail on client-side AES-GCM encryption and layered anti-analysis behavior, making t...
CrashStealer analysis of client-side AES-GCM encryption and anti-analysis techniques
Technical AnalysisAbout this happening: Researchers published a technical analysis of CrashStealer that adds reusable detail on client-side AES-GCM encryption and layered anti-analysis behavior, making t...
CrashStealer meeting-PIN delivery campaign
Campaign
H score35
First: 13.07.2026 22:04
Last: 13.07.2026 22:04
Sources 1
About this happening:
The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
CrashStealer meeting-PIN delivery campaign
CampaignAbout this happening: The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...
Asin Android spyware distribution through fake utility, PDF, and war-map apps
Malware Activity
H score22
First: 05.06.2026 17:53
Last: 05.06.2026 17:53
Sources 1
About this happening:
The Asin Android spyware activity is being distributed through fake utility, PDF, and war-map apps, putting Arabic-speaking users at risk of covert surveillance on Andro...
Asin Android spyware distribution through fake utility, PDF, and war-map apps
Malware ActivityAbout this happening: The Asin Android spyware activity is being distributed through fake utility, PDF, and war-map apps, putting Arabic-speaking users at risk of covert surveillance on Andro...
CL-CRI-1089 Operation FlutterBridge macOS malvertising campaign
Campaign
H score33
First: 04.06.2026 14:19
Last: 04.06.2026 14:19
Sources 1
About this happening:
A macOS malvertising campaign is delivering FlutterShell through malicious ads and trojanized apps, expanding browser-hijacking and backdoor risk across the U.S., Canada...
CL-CRI-1089 Operation FlutterBridge macOS malvertising campaign
CampaignAbout this happening: A macOS malvertising campaign is delivering FlutterShell through malicious ads and trojanized apps, expanding browser-hijacking and backdoor risk across the U.S., Canada...
Apple and Google Messages beta rollout of cross-platform E2EE RCS
Security Tool/Service
H score11
First: 12.05.2026 16:00
Last: 12.05.2026 16:00
Sources 1
About this happening:
Apple and Google have begun a beta rollout of end-to-end encrypted RCS between iPhone and Android devices, materially reducing carrier and in-transit visibility fo...
Apple and Google Messages beta rollout of cross-platform E2EE RCS
Security Tool/ServiceAbout this happening: Apple and Google have begun a beta rollout of end-to-end encrypted RCS between iPhone and Android devices, materially reducing carrier and in-transit visibility fo...
Timeline
-
24.04.2026 14:48 2 articles · 2mo ago
MiningDropper (BeatBanker) modular Android malware analysis
Technical Analysis UpdateCyble identified MiningDropper, also known as BeatBanker, as a layered Android malware delivery framework that targets users in India, Latin America, Europe, and Asia through trojanized Lumolight builds and fake websites impersonating banking institutions and regional transport offices. The framework combines encrypted payload staging, dynamic DEX loading, XOR-based native obfuscation, AES-encrypted payload staging, and anti-emulation techniques to deliver cryptomining, information theft, remote access, and banking malware payloads.
Show sources
- 26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — thehackernews.com — 24.04.2026 14:48
- 26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases — thehackernews.com — 24.04.2026 14:48