Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes. Android malware can use your phone to mine cryptocurrency without your knowledge. Recent campaigns have hidden Monero miners inside fake apps, sometimes alongside banking-card theft or remote-administration tools. Heat, battery drain and lag can be clues, but they do not prove malware is present.
How these Android mining campaigns work
The documented campaigns relied on deceptive apps and installation outside trusted app stores—not on evidence that ordinary apps from official stores were mining cryptocurrency. Attackers used familiar brands or a fake update prompt to persuade people to install a malicious APK. Once installed, the malware could conceal its components and activate mining when it was less likely to be noticed.
Two campaigns, different triggers and targets
| Campaign | Delivery and targeting | What it does | Mining trigger |
|---|---|---|---|
| BeatBanker, reported by Kaspersky on March 10, 2026 | Distributed as a fake Starlink application; the reported campaign description does not specify a geographic target. | Includes a Monero miner and BTMOB remote-administration tool. | Not stated in Kaspersky’s reported description. |
| Banking-app campaign, reported by McAfee Labs on August 4, 2025 | Aimed mainly at Hindi-speaking users in India. Phishing pages impersonated SBI Card, Axis Bank, IndusInd Bank, ICICI and Kotak financial apps and offered malicious APK downloads. | Collected names and payment-card details through fake financial screens, and also mined Monero. | Remote activation through Firebase Cloud Messaging (FCM). |
| Fake “Axis Card” app, described by Quick Heal / Seqrite Labs in 2025 | Delivered from a phishing site; the bulletin does not state a broader geographic target. | Covert cryptocurrency mining. | Started mining when the phone was locked and stopped when it was unlocked. |
Why the banking campaign was difficult to spot
McAfee found phishing pages that copied legitimate Indian banking-site assets. After installation, the first-stage app displayed a fake Google Play update screen. Encrypted DEX files were decrypted and loaded in two stages, a method that can make the payload harder to identify through static analysis. The malware could collect names, card numbers, CVVs and expiration dates through counterfeit financial screens and send them to attacker-controlled infrastructure.
Mining did not necessarily run continuously. McAfee observed the malware receiving an FCM command, downloading an encrypted native binary and executing it with XMRig-compatible arguments to mine Monero. A command-controlled trigger can make activity intermittent rather than obvious whenever the app is open.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Why screen-lock mining matters
Quick Heal / Seqrite Labs described a related “Axis Card” app that mined only while the phone was locked, then stopped when it was unlocked. Its 2025 bulletin reports that the app “allocates over 2.3 GB of RAM and eight CPU threads after each lock event, rapidly increasing device temperature from 32 °C to 45 °C within 30 minutes.” Those figures describe the bulletin’s observation of that app, not a diagnostic threshold for Android malware generally.
Signs that deserve investigation
Mining consumes device resources. The National Institute of Standards and Technology (NIST) classifies abusive mobile computation as a resource-consumption threat that can increase use of battery power, computational power, network bandwidth, data limits or storage. A phone that becomes hot, drains its battery unusually quickly or slows down may therefore warrant a closer look—especially if the change began after installing an APK from a link or website.
Rank #2
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
- Heat: the phone gets unusually warm while idle or locked.
- Battery drain or lag: battery life drops or normal tasks become sluggish without an obvious explanation.
- Unexpected app or update prompts: a website or unfamiliar app asks you to install an APK or claims a Play update is required.
These symptoms are clues, not proof: other apps, heavy use and device problems can also cause heat, drain or slow performance. Likewise, a malicious app may activate only under certain conditions, so the absence of constant symptoms does not rule it out.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Quick Recap
Best Value
- POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
- IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
- ALWAYS UP TO DATE: Webroot scours 95% of the internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates
- SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
- NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Rank #3
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
What to do if you suspect a mining app
- Stop interacting with the suspicious app. Do not enter payment details or passwords into its screens. If you suspect it has collected card information, use a different, trusted device to contact your bank or card issuer, report the possible exposure and follow its instructions for securing or replacing the card.
- Remove the app. In Android Settings, open Apps or the equivalent app-management screen, select the unfamiliar or recently installed app and choose Uninstall. Menu names vary by Android version and phone maker. If you cannot identify the app, review recently installed apps and compare their names with what you deliberately installed.
- Run a security scan and update the device. Use a reputable mobile-security tool to scan for suspicious apps, then install available Android and security-app updates. McAfee says its Mobile Security detects the apps it identified as High-Risk threats; Quick Heal says its Mobile Security detects and blocks Android.Dminer.A using behavioral analysis, including suspicious background processes and mining-pool connections. Detection depends on the product and identified threat; a scan result is not a guarantee that every compromise has been found.
- Change exposed credentials from a clean device. If you entered banking credentials into a fake screen, contact the financial institution and change the affected credentials using its official app or website. Watch for transactions or account activity you do not recognize.
- Consider a factory reset if compromise is confirmed or persists. Back up essential personal files first, but avoid restoring the suspicious APK or other apps you do not trust. A reset removes local apps and data, so follow the phone maker’s instructions and make sure you can access the accounts needed to set the phone up again.
How to reduce the risk of another infection
- Install apps from official app stores rather than links in messages, search ads or unfamiliar websites. NIST’s APP-38 guidance says: “To reduce the risk of installing apps with trojan functionality, only download apps from official app stores.”
- Reject unexpected requests to install an APK or a purported update from a website. Open the relevant official app or store yourself to check for updates.
- Keep Android and security tools current, and investigate unexpected device heat, battery drain or slowdown—particularly after installing an app from outside a trusted store.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

