Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - From Crypto Currency Mining To DDos Attacks: The New Multi-Featured Mobile Trojan Loapi Discovered
News & Analysis

From Crypto Currency Mining To DDos Attacks: The New Multi-Featured Mobile Trojan Loapi Discovered

ISBuzz TeamBy ISBuzz TeamDecember 20, 2017Updated:August 5, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Large 2,200x DDoS Amplification Assault Due To New SLP Flaw
Large 2,200x DDoS Amplification Assault Due To New SLP Flaw
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Kaspersky Lab researchers have identified a new intriguing malware with multiple modules, which allows for an almost endless number of malicious features – from crypto currency mining to DDos attacks. Due to its modular architecture, even more functions can be added to it. This unusual and powerful malicious software is called Loapi.

Loapi stands out from the crowd of various single-functional Android malware, including banking Trojans, crypto mining Trojans, etc., because it has a complex modular architecture that allows it to perform almost limitless actions on a compromised device.

The Loapi Trojan is being spread through advertising campaigns under the guise of antivirus solutions or apps for adults. Once installed, applications request device admin rights and then discreetly initiate communications with command and control servers to install additional modules.

The architecture includes the following modules:

  • Adware module– used for the aggressive display of advertising on the user’s device,
  • SMS module– used by the malware to perform various operations with text messages,
  • Web crawlermodule – used to subscribe users to paid services without them knowing. The SMS-module will hide messages from the user, respond to them as needed, and then remove all the “evidence”,
  • Proxy module– allows attackers to execute HTTP requests on behalf of the device. These actions can be performed for DDoS attacks,
  • Monero miner module– used to mine the crypto currency Monero (XMR).

As well as its excessive volume of features, Loapi has the capacity to protect itself. As soon as a user tries to revoke device admin rights, the malware blocks the device’s screen, and closes the window. In addition to this standard protection technique, Loapi can receive a list of applications that are dangerous to it from the command and control servers – these are often security solutions, which intend to remove the malware. If an installed or running application is on the list, the Trojan shows users a fake message saying malicious software has been found, and offering users the chance to remove the application. The message is shown in a loop, thus, even if the user refuses to delete the app at first, the message will be displayed again and again until the user finally agrees.

Besides the Loapi approach to self-defense, Kaspersky Lab research has also found an interesting twist: tests on one randomly selected mobile phone demonstrated that the malware creates such a heavy workload on an infected device, that it even heats it up, and can deform its battery. Apparently, the malware’s authors hardly wanted this to happen, as they are hungry for as much money as they can get by keeping the malware running. But their lack of attention to the malware’s optimisation has led to this unexpected physical “attack vector” and possibly serious damage to user devices.

“Loapi is an interesting representative of the world of Android malware because its authors have embodied almost every feature possible into its design. The reason behind that is simple – it is much easier to compromise a device once and then to use it for different kinds of malicious activity aimed at earning illegal money. The surprisingly unexpected risk which this malware brings is that even though it can’t cause direct financial damage to the user by stealing their credit card data, it can simply destroy the phone. This is not something you would expect from an Android Trojan, even a sophisticated one.” notes Nikita Buchka, security expert at Kaspersky Lab.

According to the research, Loapi could possibly be linked to Trojan.AndroidOS.Podec. This is due to the fact that both Trojans gather similar information for the command and control server at the start. They also have similar obfuscation methods.

Kaspersky Lab researchers advise users to follow these measures in order to protect their devices and private data from possible cyberattack:

  • Disable the ability to install applications from sources other than official app stores
  • Keep the OS version of your device up to date in order to reduce vulnerabilities in the software and lower the risk of attack
  • Install a proven security solution in order to protect your device from cyberattack

Find more about the Loapi Trojan on Securelist.com.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

How to Protect Your VoIP System from DDoS Attacks

September 9, 20258 Mins Read

Pro-Russian Cybercrime Group NoName057(16) Hit Hard in Global Takedown

July 18, 20255 Mins Read

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}