MiningDropper is a modular, multi-stage Android malware delivery framework used to distribute cryptocurrency miners as well as secondary payloads including infostealers, remote access trojans, and banking malware. It has been observed in fast-growing campaigns in which malicious APKs are disguised as legitimate apps and distributed via phishing pages, smishing, social media links, and fraudulent websites impersonating transport portals, banks, telecom brands, and popular mobile applications. Reporting linked activity to campaigns targeting users in India and broader regions including Europe, Latin America, and Asia. CRIL also stated that MiningDropper is referred to as BeatBanker.
Technically, MiningDropper uses layered evasion and staged execution to reduce detection. Observed samples used a trojanized version of the open-source Android project LumoLight. Malicious execution was launched through the native library librequisitionerastomous.so, which used XOR-obfuscated strings decrypted at runtime, checked platform details, system architecture, and device model information for emulator or rooted-environment detection, and terminated malicious activity when suspicious environments were detected. When checks passed, it decrypted the asset x7bozjy2pg4ckfhn with a hardcoded XOR key to produce a first-stage DEX payload, which was loaded dynamically with DexClassLoader. That stage decrypted a second-stage file with AES; one analyzed sample used the file 4ozvcznaamqmioqf/sorxbqp8 with key material derived from the first 16 bytes of the SHA-1 hash of the filename. The second stage displayed a fake Google Play update screen while decrypting additional components and selecting either a miner path or a user-defined payload path.
In the user-defined payload branch, MiningDropper decrypted jajmanpongids into a ZIP archive containing third-stage installer components, including the DEX file enchantmentcrosses and ARM native libraries, then reconstructed split payload components such as transnaturationsaxhorn, mischanterperilling, and unwieldlyostearthritis to install the final package. In analyzed cases, the final payload was BTMOB RAT. Reported capabilities of that final payload included WebView-based credential theft, keylogging, data exfiltration, Accessibility Service abuse, real-time remote control, screen monitoring, file management, audio recording, and command execution, enabling device takeover and financial fraud. In the miner branch, MiningDropper decrypted bilbopseudomelanosis into a standalone APK for cryptocurrency mining.
Cyble/CRIL reported more than 1,500 MiningDropper samples observed in one month, with many showing very low antivirus detection; more than half had low detection rates, and one large cluster of about 668 samples had only three detections. A specifically analyzed sample was distributed as Free Secure – Annulation.apk with SHA-256 58a94f889547db8b2327a62e03fb2cce3bda716278d645ee8094178ecda2e9e6. High-confidence associated artifacts mentioned in reporting include librequisitionerastomous.so, x7bozjy2pg4ckfhn, 4ozvcznaamqmioqf/sorxbqp8, jajmanpongids, enchantmentcrosses, bilbopseudomelanosis, and the dynamically loaded class com.example.virusscanbypassbootstrapper.DexLoader.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Inside that library, strings are hidden with XOR obfuscation and decrypted only at runtime, making the code harder to inspect and easier to keep below detection thresholds.
A fast growing Android malware campaign is using a framework called MiningDropper to push far more dangerous threats onto phones disguised as normal apps.
The same native component also checks platform details, system architecture, and device model information to decide whether it is running inside an emulator or rooted environment. If the environment looks suspicious from the attacker’s view, the malware can stop its harmful activity.
The same native component also checks platform details, system architecture, and device model information to decide whether it is running inside an emulator or rooted environment. If the environment looks suspicious from the attacker’s view, the malware can stop its harmful activity.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage Android malware framework used to deliver additional payloads onto infected devices. It uses native code, encrypted assets, dynamic DEX loading, XOR/AES decryption, and anti-emulation checks to evade analysis, and can ultimately deploy infostealers, RATs, banking malware, or cryptocurrency miners.
A modular multi-stage Android malware delivery framework that uses native code, XOR obfuscation, AES-encrypted staged payloads, dynamic DEX loading, anti-emulation, and configuration-driven delivery to install either a cryptocurrency miner or additional payloads such as infostealers, banking malware, and RATs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.