Friday, March 21, 2025
HomeMalwareAndroid Cryptocurrency Mining Malware Infecting Amazon Fire TV & Other Amazon Devices

Android Cryptocurrency Mining Malware Infecting Amazon Fire TV & Other Amazon Devices

Published on

SIEM as a Service

Follow Us on Google News

Android-based cryptocurrency mining malware now started infecting Amazon Fire TV & Fire TV Stick Devices.

It doesn’t specifically target the Amazon devices but Amazon Fire TV devices are running with an Android operating system so the cryptocurrency malware infection spreading across the Amazon devices.

Multiple Fire TV device owners are facing this infection while they are streaming media players and many compliant are registered in XDA forums.

This Mining Malware named as  ADB.Miner that was discovered earlier this year and it rapidly spreading through Android-based devices.

In this case, A particular version of this Mining malware started appearing on Amazon devices and installs itself as an app called “Test” with the package name “com.google.time.timer”. 

Once the malware penetrated to the device, it consumes the infected device resources and utilizes the cryptocurrency mining process, also it tries to spread itself to other Android devices on the same network.

Amazon Fire TV Infection Process

Malware infection process starts by installing the app on Amazon Fire TV and it is still unknown that which app is installing the malicious mining file to infecting the device.

Researchers believe that malware spreading while users trying to download the Apps that used to watch pirate movies or TV shows.

According to aftvnews Once an initial device is infected, the malware can spread itself to other devices over ADB, even if those other devices never had apps sideloaded.

Initial infection is slowly started in the infected device and it slows down the system process and  Loading apps will take longer than usual.

Later Malware utilizes the device and consuming 100% of the device resources to mining the cryptocurrency.

Also, A screen that says “Test” with a green Android robot icon will also occasionally appear randomly on infected devices.

It leads to stop the video playback and apps that makes very difficult to use it normally by infected user.

Prevention Methods

To make it impossible for your Fire TV device to become infected by this malware, go to your Fire TV device’s Settings and select the “Device” menu item.

Then select “Developer options” and ensure that “ADB debugging” and “Apps from Unknown Sources” are both set to “OFF”. These settings are off by default, so if you’ve never changed them, then you have always been safe from this malware.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Attackers Leverage Weaponized CAPTCHAs to Execute PowerShell and Deploy Malware

In a recent surge of sophisticated cyberattacks, threat actors have been utilizing fake CAPTCHA...

Researchers Uncover FIN7’s Stealthy Python-Based Anubis Backdoor

Researchers have recently discovered a sophisticated Python-based backdoor, known as the Anubis Backdoor, deployed...

Researchers Reveal macOS Vulnerability Exposing System Passwords

A recent article by Noah Gregory has highlighted a significant vulnerability in macOS, identified...

JumpServer Flaws Allow Attackers to Bypass Authentication and Gain Full Control

JumpServer, a widely used open-source Privileged Access Management (PAM) tool developed by Fit2Cloud, has...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Attackers Leverage Weaponized CAPTCHAs to Execute PowerShell and Deploy Malware

In a recent surge of sophisticated cyberattacks, threat actors have been utilizing fake CAPTCHA...

New Steganographic Malware Hides in JPEG Files to Spread Infostealers

A recent cybersecurity threat has been identified, where steganographic malware is being distributed through...

Massive “DollyWay” Malware Attack Compromises 20,000+ WordPress Sites Worldwide

A significant malware operation, dubbed "DollyWay," has been uncovered by GoDaddy Security researchers, revealing...