Cybersecurity researchers have detected a significant change in the Android malware landscape, where dropper applications, which were traditionally used to deliver banking trojans, now distribute simpler malware, such as SMS stealers and basic spyware. According to a report by ThreatFabric, these campaigns are designed to hide behind government or banking applications in India and other regions of Asia.
Beware of your Android!
This change is attributed to the new security protections implemented by Google in selected markets such as Singapore, Thailand, Brazil, and India, which aim to block the installation of suspicious apps that require dangerous permissions. Although Google Play Protect has strengthened its defenses, attackers continue to find ways to bypass these measures, demonstrating a constant battle between security and cybercriminals.
Attackers even encapsulate the most basic payloads within a dropper, which provides them with a layer of protection that can evade current security checks. This approach allows cybercriminals to continue offering seemingly harmless applications, only displaying their malicious behavior when the user agrees to install the application.

One of the identified dropper applications is RewardDropMiner, which has been used to distribute spyware payloads, as well as a Monero cryptocurrency miner. However, recent versions of this dropper no longer include mining functionality. Other variants like SecuriDropper and HiddenCatDropper have shown similar tactics to avoid triggering alarms in Google Play Protect.
Additionally, a new campaign has also been detected, using malicious ads on Facebook to promote a premium version of the TradingView app, with the aim of deploying an advanced banking trojan. To date, more than 75 deceptive ads have been run, reaching tens of thousands of users in the European Union, highlighting the adaptability of cybercriminals to current user trends.