Android Smartphones, Next Target for Cryptocurrency Malware
Cryptocurrency malware, also known as CoinMiner, continues to spread using the CPU of infected systems. Recently, it began to expand its target from PCs and server systems to Android smartphones.
Android cryptocurrency malware can be divided into three main categories: Cryptojacking for mining cryptocurrency without the user's knowledge, FakeWallet that disguises itself as a cryptocurrency wallet, and Clipper that intercepts and swaps wallet-related information from the clipboard.
Type 1: Cryptojacking
Cyprojacking
CoinMiner embeds itself in a mobile game called Bug Smasher. Once the game
starts, there is a sudden increase in CPU usage. The user is tricked into thinking
that they are playing the real game application while mining secretly takes
place.

Figure
1 | Screenshot of Bug Smasher
Type 2: FakeWallet
FakeWallet
pretends to be a wallet application for cryptocurrency. The application
generates a new wallet address that is assumed to be that of the attacker.
Another method of FakeWallet is to impersonate an existing cryptocurrency
wallet and gets the user to enter their private key.

Figure
2 | Fake MyEtherWallet application using MyEtherWallet's logo
Type 3: Clipper
Clipper monitors
the clipboard for the infected device and checks the user’s wallet information.
Once detected, it sends the information to the attacker and tampers with the
address that the user has pasted.
As a
result, users are advised to take a cautious look into the services that they allow
on their smartphones, especially JavaScript, to avoid being an easy target for
cryptocurrency mining.
AhnLab
V3 Mobile Security, anti-malware application for Android, detects the relevant
mobile coin miners under the following aliases:
<V3 Mobile Security Aliases>
Android-PUP
CoinMiner
Android-Trojan/FakeWallet
Android-Trojan/Clipper