Saturday, April 12, 2025
HomeMalwareNew Android Malware Physically Destroying your Phone by Running Cryptocurrency miner

New Android Malware Physically Destroying your Phone by Running Cryptocurrency miner

Published on

SIEM as a Service

Follow Us on Google News

Nowadays Trojanized Android apps evolving rapidly in play store and continuously targetting users, a new malware strain Trojan.AndroidOS.Loapi spotted consist of modular architecture which is capable of performing multiple attacks.

Security researchers from Kaspersky labs discovered the trojan dubbed “Loapi” which can damage the phone by downloading a Monero mining module which generates a constant load that makes the battery bulged and damages the phone cover.

Loapi

How the Malicious files Distributed – Loapi

Loapi is not reached play store, they are distributed through advertising campaigns. It hides behind some Antivirus, adult content apps, researchers found more than 20 sources that distribute Loapi. Users are redirected to the attacker’s malicious website and the file downloaded from there.

- Advertisement - Google News

Once it installed it checks for the root permission, but it doesn’t use root privileges, the applications keep on trying to get device administrator permissions.

Execution and Self-Protection

Loapi if obtains admin permissions it performs various activities and it won’t allow users to revoke the device manager permissions by using standard and forcing users to uninstall legitimate Antivirus by posing endless stream of popups.

Initially, it downloads the malicious app file and the second stage the DEX payload which sends the device information to the C&C servers, with the third stage the modules are downloaded and initialized.

Also Read New sophisticated Malware campaign Leveraging NSA Exploits to Mine Monero on Windows and Linux Systems

Modules Installed

Advertisement module: Involved in the progress of aggressive ads displaying.
SMS module: used in Sending requests to C&C
Web crawling module: used in Hidden Javascript execution
Proxy module: HTTP proxy server used to organize DDoS attacks
Mining Monero: Used to perform to perform Monero (XMR) cryptocurrency mining

C&C Servers

ronesio.xyz (advertisement module)
api-profit.com:5210 (SMS module and mining module)
mnfioew.info (web crawler)
mp-app.info (proxy module)

Researchers found Loapi connected with Trojan.AndroidOS.Podec they are having similar techniques with obfuscation, functionality and detecting root permissions for the device.

Researchers called it as “jack of all trades” creators have implemented almost the entire spectrum of techniques for attacking devices: the Trojan can subscribe users to paid services, send SMS messages to any number, generate traffic and make money from showing advertisements, use the computing power of a device to mine cryptocurrencies, as well as perform a variety of actions on the internet on behalf of the user/device.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

TROX Stealer Harvests Sensitive Data Including Stored Credit Cards and Browser Credentials

Cybersecurity experts at Sublime have uncovered a complex malware campaign revolving around TROX Stealer,...

GOFFEE Deploys PowerModul in Coordinated Strikes on Government and Energy Networks

The threat actor known as GOFFEE has launched a series of targeted attacks against...