216.73.217.22

GPT Trade: Fake Google Play Store drops BTMob Spyware and UASecurity Miner on Android Devices

· Published 19/11/2025 08:56 · Modified 19/11/2025 09:35

Export JSON

Essential information

Published
19/11/2025 08:56
Modified
19/11/2025 09:35
Tags
2025-11-19 android apk packer btmob cryptocurrency miner dropper fake app store gpt trade modular malware social engineering spyware uasecurity miner
Related entities
10 observables, 3 malware

Description

A sophisticated impersonating the Google Play Store was discovered, distributing an app called ''. This malicious application, disguised as an AI trading assistant, actually deploys two dangerous payloads: and . The creates directories, unpacks components, and generates new APK files before silently installing the malware. grants extensive device access, enabling credential theft and surveillance. focuses on persistence and remote control. The attack chain involves , APK generation, third-party packer services, and multiple command and control endpoints, reflecting a growing trend in modular threats.

External references