Skip to content
ThreatCluster

MiningDropper Framework Delivers Multiple Malware Types on Android Devices

First seen 20 Apr 2026, 11:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 21, 2026 at 11:54 UTC

Hackers are leveraging a modular Android framework known as MiningDropper to distribute various forms of malware, including infostealers, remote access trojans (RATs), and banking malware. This multi-stage dropper system can also facilitate cryptocurrency mining on compromised devices. The campaign targets Android users by disguising malicious payloads as legitimate applications. Researchers have noted a rapid increase in the scope of this malware campaign, affecting a wide range of Android devices. Specific malware types associated with MiningDropper include BTMOB RAT and credential-stealing spyware. The current status indicates ongoing exploitation with no immediate resolution in sight. Users are advised to remain vigilant against suspicious applications and potential malware infections.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 159d ago How this analysis works

Timeline

2026-04-20
MiningDropper malware campaign reported in cybersecurity articles.

More articles in this cluster (2)

Following this threat?

Track Btmob in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed