Bitcoin Info News Logo
Bitcoin NewsAlt Coin NewsMiningBlockchain EventMillionaireCrypto NewsNews
Bitcoin NewsAlt Coin NewsMiningBlockchain EventMillionaireCrypto NewsNews
Sponsorship
Sponsorship
Home/Crypto News/Brazilian Hackers Use Fake Google Play Store to Mine Crypto and Steal USDT
Crypto News

Brazilian Hackers Use Fake Google Play Store to Mine Crypto and Steal USDT

John Kojo Kumi
John Kojo Kumi
Bitcoin Info News Logo

Bitcoin Info News is an independent digital publication focused on Bitcoin, crypto markets, blockchain infrastructure, regulation, and adoption.

Follow on Google

Contact the editorial teamView newsroom and editorial contacts

Social

FacebookYouTubeTelegramXLinkedIn
Published:Mar 22, 2026
Last updated:Jun 8, 2026
4 MIN READ
MakeBitcoin Info Newspreferred onGoogle

Brazilian hackers are distributing malware through a fake Google Play Store that hijacks Android phones for cryptocurrency mining and drains USDT from victim wallets.

A cybersecurity campaign targeting Android users in Brazil has been distributing malware through a fake version of the Google Play Store, hijacking phones for cryptocurrency mining and stealing USDT from victim wallets. The scheme highlights an escalating trend of dual-purpose mobile malware designed to exploit crypto holders in emerging markets.

How the Fake Google Play Store Delivers Malware to Android Users

The attack relies on a counterfeit app storefront that mimics the official Google Play Store interface. Victims are typically directed to the fake store through phishing links distributed via SMS messages, WhatsApp, and social media ads, according to a report from PANews.

Once users land on the spoofed page, they are prompted to download APK files that request extensive device permissions, including access to accessibility services, SMS, and clipboard functions. These permissions give the malware deep control over the device without raising obvious alarms for less technical users.

The campaign follows a pattern consistent with other Android malware operations documented in Brazil. Security researchers have previously identified fake government apps used to distribute Android malware in the country, suggesting threat actors are adapting proven social engineering tactics to target crypto-holding populations.

Brazil’s growing crypto adoption rate makes its users a high-value target. The fake store domains are designed to closely replicate legitimate Google Play URLs, making visual inspection alone insufficient to distinguish them from the real platform.

Two Payloads: Crypto Mining Hijack and USDT Wallet Drain

The malware carries a dual-purpose payload. The first component silently deploys a cryptocurrency miner that consumes the device’s CPU resources, causing battery drain, overheating, and degraded performance. Mining operations of this type typically target Monero (XMR) due to its CPU-friendly mining algorithm and privacy features that obscure transaction trails.

The second, more financially damaging component targets USDT holdings directly. The malware uses clipboard hijacking to intercept wallet addresses copied by the user, silently replacing them with attacker-controlled addresses before the transaction is sent. This technique has been documented in the BeatBanker trojan family, which spreads through similar phishing-based distribution methods.

The USDT theft component is the greater financial threat. While the mining payload generates small returns over time through passive resource abuse, a single intercepted USDT transfer can drain thousands of dollars in seconds. Victims often do not realize the substitution has occurred until after the transaction confirms on-chain.

Both TRC-20 (Tron) and ERC-20 (Ethereum) versions of USDT appear to be at risk, as clipboard hijackers can be configured to detect and swap addresses for multiple blockchain networks. Users of popular mobile wallets including MetaMask and Trust Wallet should exercise particular caution, as these are common targets for this class of malware.

The dual-payload approach mirrors a broader trend in crypto-targeting mobile malware that maximizes revenue from each compromised device. The mining component generates ongoing passive income while the wallet drainer waits for high-value transactions to intercept.

This type of attack underscores the risks facing mobile crypto users. Earlier incidents, such as when Fluid suspended its USR marketplace after a security incident, demonstrate that threats to crypto holdings come from multiple vectors. Similarly, Lido’s response to the Resolv Labs vulnerability attack showed how quickly exploits can be weaponized against DeFi users.

How to Spot Fake App Stores and Protect Your Crypto on Android

The most effective defense is to never install APK files from links received through SMS, WhatsApp, Telegram, or social media ads. Only download apps through the official Google Play Store app pre-installed on your device.

Verify that Google Play Protect is enabled by opening the Play Store app, tapping your profile icon, and selecting “Play Protect.” This built-in scanner checks apps for known malware signatures before and after installation.

Clipboard hijacking is invisible to the user during normal operation. Before confirming any crypto transaction, always verify the full recipient wallet address character by character after pasting. Comparing only the first and last few characters is not sufficient, as sophisticated malware generates addresses that match those segments.

For users holding significant crypto balances, a hardware wallet or a dedicated device that is not used for general browsing and app installation provides a stronger security boundary. Keeping large holdings on the same phone used for daily browsing, messaging, and app downloads creates unnecessary exposure to exactly this type of attack.

Additional protective measures include disabling the “Install from Unknown Sources” setting in Android’s security options and regularly reviewing installed apps for any unfamiliar entries. Users who suspect their device may be compromised should perform a factory reset rather than simply uninstalling suspicious apps, as some malware persists through standard removal.

The growing sophistication of mobile crypto malware reflects broader market pressures that make digital asset holders attractive targets. As stablecoin adoption expands across Latin America, security researchers expect phishing campaigns targeting USDT holders to increase in frequency and complexity throughout 2026.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Article Topics

Crypto News

Editor Picks

If You Only Read 3 Things Today

Fastest way to catch the signal before you keep scrolling.

#1 Galaxy 40 of Coldcard s Second...#2 ECB Says Stablecoin Deposit Rule Could...#3 Bitcoin ETF Inflows Hit 715M as...

Most Read

1

Galaxy: 40% of Coldcard’s Second Hack Wave Linked to White Hats

Sep 23, 2026•3 MIN READ
2

ECB Says Stablecoin Deposit Rule Could Hurt EU Banks

Sep 23, 2026•4 MIN READ
3

Bitcoin ETF Inflows Hit $715M as Four-Day Total Tops $2.3B

Sep 23, 2026•2 MIN READ
4

U.S. Bitcoin ETFs Draw $1.7B in Net Inflows in Two Days

Sep 23, 2026•3 MIN READ
5

Bitcoin Breaks Above $85,000 as Crypto Liquidations Hit $747M

Sep 23, 2026•2 MIN READ

Quick Categories

Bitcoin News
Alt Coin News
Mining
Blockchain Event
Millionaire

Partnerships

Advertise With Us

Reach active Bitcoin readers, builders, and spenders.

Learn More
Megaphone
CoinMarketCap

Company

  • About Us
  • Authors
  • Masthead
  • Team Verification
  • Contact Us

Resources

  • RSS Feeds
  • Editorial Policy
  • Corrections Policy
  • Terms of Service
  • Privacy Policy
  • Disclaimer
  • Sitemap

Tools

Quick access to the site tools and map-driven utility pages.

BTC Merchant MapToolMerchants by CountryToolTop Merchant CountriesToolGovernment Holdings MapTool

Coverage

RSS Feeds

Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.

Bitcoin NewsDeskAlt Coin NewsDeskMiningDeskBlockchain EventDeskMillionaireDeskCrypto NewsDesk

© 2026 BitcoinInfoNews.com. All rights reserved.

Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.

Crypto News
News
Others