Google removes five wallpaper apps secretly mining bitcoins

Mobile & tablets

by CBR Staff Writer| 28 April 2014

Malware runs in background, targeting online devices with more than 50% battery.

Google has removed five wallpaper apps from the Play store said to be secretly using mobile resources to mine bitcoins.

According to security firm Lookout, the applications run when the display is off, draining the battery.

The bug, BadLepricon, operates similarly to the other bitcoin mining malware, targeting devices an active internet connection and more than half the battery left.

Researchers said a recent mining experiment using 600 quadcore servers could only generate 0.4 Bitcoins per year, with malware makers directing their efforts towards "low-hanging fruit" to maximise resources.

Lookout security researcher Meghan Kelly said miners often don't work alone because of the difficulty of bitcoin mining,

"Instead, they work in groups, pooling their processing resources," Kelly added in a blog. "They collect payment as a percentage of the processing power they contribute,"

In order to control the sometimes thousands of bots, the malware author may use a proxy to set up one point of contact.

BadLepricon uses a Stratum mining proxy, allowing the author to easily change mining pools or connections to Bitcoin wallets.

The apps were variously themed around anime girls, "epic smoke" and attractive men, and had been installed 100-500 times each at the time of removal.

After installation, BadLepricon entered an infinite loop, checking every five seconds for battery level, connectivity, and whether the phone's display was on. It also made use of WakeLock, a feature that ensures that your phone doesn't go to sleep even if the display is off.

Post a comment

Comments may be moderated for spam, obscenities or defamation.
Privcy Policy

We have updated our privacy policy. In the latest update it explains what cookies are and how we use them on our site. To learn more about cookies and their benefits, please view our privacy policy. Please be aware that parts of this site will not function correctly if you disable cookies. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy unless you have disabled them.