BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Android Droppers Evolve to Bypass Google Protections, Spread Malware

Android Dropper Apps Evolve to Bypass Security and Spread Malware Across Asia and Europe

  • Cybercriminals are using Android dropper apps to deliver both advanced and basic types of Malware, including SMS stealers and spyware.
  • Attackers disguise these droppers as official government or banking apps, mainly targeting users in India and Asia.
  • Google’s new security measures block many suspicious sideloaded apps, but attackers modify droppers to bypass these safeguards.
  • One dropper, RewardDropMiner, has deployed several malicious apps in India and previously included cryptocurrency mining features.
  • A related campaign uses Facebook ads to spread a fake TradingView app, infecting European users with the Brokewell banking trojan.

Cybersecurity researchers have identified a shift in Android malware delivery, where dropper apps now distribute both sophisticated banking trojans and simpler threats like SMS stealers and basic spyware. These droppers are being presented as official government and banking apps, with the primary targets in India and other parts of Asia.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Dutch security firm ThreatFabric reported that recent updates to Google Play Protect—especially a Pilot Program in Singapore, Thailand, Brazil, and India—are blocking suspicious sideloaded apps requesting sensitive permissions. Despite these advances, attackers have adapted their droppers to avoid high-risk permissions and display innocuous screens until users interact further and receive the harmful payload.

According to ThreatFabric, “By encapsulating even basic payloads inside a dropper, they gain a protective shell that can evade today’s checks while staying flexible enough to swap payloads and pivot campaigns tomorrow.” If users accept warnings and proceed to install the app, the dropper can bypass protections and deliver the malware. The dropper then requests the permissions it needs to operate.

Examples of malicious apps spread through the RewardDropMiner dropper in India include PM YOJANA 2025, RTO Challan, SBI Online, and Axis Card. Newer versions of RewardDropMiner have removed their previous cryptocurrency mining abilities. Other droppers detected in similar campaigns are SecuriDropper, Zombinder, BrokewellDropper, HiddenCatDropper, and TiramisuDropper.

A Google spokesperson told The Hacker News that, while these threats have not been found in the Play Store, “Google Play Protect helps to keep users safe by automatically checking it for threats … no apps containing these versions of this malware have been found on Google Play. We’re constantly enhancing our protections to help keep users safe from bad actors.”

- Advertisement -

Bitdefender Labs also warned about a campaign leveraging malicious Facebook ads to promote a counterfeit TradingView app, which delivered the Brokewell banking trojan to Android devices in the European Union. This operation has delivered at least 75 ads since late July 2025, also using fake financial and cryptocurrency apps to target Windows users.

Researchers say attackers are adjusting their methods to continue bypassing protections, showing the ongoing challenge in securing mobile platforms.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

War Sparks Cash Rush, Gold & Bonds Dumped

Bitcoin is under pressure as investors flee to cash, with Bitcoin retesting $67,500 support...

Circle Shares Plummet 20%; Tether Audit, Yield Bill Weigh

Circle's stock (CRCL) plummeted 20% on Tuesday, erasing recent gains.Rival Tether announced a major...

Robinhood announces $1.5B buyback plan over three years

Robinhood announced a new share repurchase program for up to $1.5 billion.The firm's shares...

Nearly All Pump Fun Traders Made Under $500

Over 96% of wallets trading Pump Fun-launched tokens have netted less than $500 in...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading