Monero Cryptominers Use Google Play and Picture of Scarlett Johansson

Mining Monero
Journalist
Journalist
Sead FadilpašićVerified
Part of the Team Since
Jan 2018
About Author

Sead specializes in writing factual and informative articles to help the public navigate the ever-changing world of crypto. He has extensive experience in the blockchain industry, where he has served...

Last updated: 

While malicious cryptominers are nothing new on the internet, it is still possible to be surprised by the ways people are hiding them.

This infected image has been deleted. Source: Imperva

Imperva, an American provider of data and application security solutions, identified a new but unusually distributed Monero cryptominer scam campaign involving the face of American actress and singer Scarlett Johansson, according to the company’s blog post.

These researchers believe that the malware was embedded into the photo as a way to deceive security products, since the technique of appending binary code, which was used to hide the miner, to authentic image files or documents can mutate the file, which can then bypass most anti-virus software.

“The attackers wanted to download their latest piece of malicious code, so they hosted it as an image in imagehousing.com, a legit place to host and share your images freely,” the researchers said.

When the picture was scanned at the VirusTotal service, just three anti-virus programs detected the file as malicious. When the embedded crypto-mining program was individually scanned, then 18 anti-virus programs detected it, according to the company.

Cryptominers embedded in apps are not a rarity either. Only recently, an Apple-approved calendar app was found to be mining crypto for its developers in lieu of people paying for its premium features.

Two new ones were found by a cybersecurity firm Avast on Google Play app store, called SP Browser and Mr. MineRusher. The apps are said to have a combined subscriber base in the thousands. According to the company, the mobile mining process begins once a user downloads the application and opens it, without needing to make any further action.

However, in the blog post, Avast also said that these developers don’t really gain all that much because “cryptomining campaigns require large-scale computing power in order to generate enough coins for a profitable return on investment. Unlike desktop computers, mobile devices lack the computing power for an attacker to make any substantial monetary gain.”

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,129,067,302,117
1.19
Trending Crypto

More Articles

Blockchain News
Asia Market Open: Bitcoin Holds $88K as Regional Markets Dip In Thin Year-End Trade
Shalini Nagarajan
Shalini Nagarajan
2025-12-31 02:15:51
Bitcoin News
Footballer David Beckham-Backed Healthcare Firm Will no Longer Buy Bitcoin
Sujha Sundararajan
Sujha Sundararajan
2025-12-31 00:27:08
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors