Android.CoinSteal is an Android cryptocurrency-stealing trojan family identified by Doctor Web, including variants such as Android.CoinSteal.202, .203, and .206. It was distributed as fake cryptocurrency-related Android applications, including apps disguised as official software from the dYdX crypto exchange and the Raydium and Aerodrome Finance blockchain platforms. The trojans prompted victims to enter their wallet mnemonic seed phrase and then transmitted that phrase to the attackers, enabling theft of cryptocurrency assets. Doctor Web also reported Android.CoinSteal variants among more than 180 threats found on Google Play in the prior 12 months, contributing to over 2.165 million total downloads across all identified threats. High-confidence behavior directly mentioned in the content is credential harvesting of wallet recovery phrases via trojanized Android apps posing as legitimate crypto software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crypto-stealing trojan family distributed via Google Play masquerading as legitimate crypto exchange/blockchain apps; phishes wallet mnemonic phrases and exfiltrates them to attackers.
Crypto-stealer trojan family distributed via Google Play masquerading as legitimate crypto exchange/blockchain apps; phishes mnemonic phrases (sometimes via forms spoofing other platforms) and exfiltrates them to attackers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.