GPT Trade: Fake Google Play Store drops BTMob Spyware and UASecurity Miner on Android Devices
A recently discovered Android campaign leverages a fake Google Play Store to distribute GPT Trade, a malicious dropper posing as a ChatGPT-themed trading app. Once installed, the dropper silently generates and deploys two additional malware families—BTMob spyware and the UASecurity Miner—while redirecting the user to the real ChatGPT website to hide the compromise. The operation combines social engineering, dynamic APK generation, and an APK “protection” service distributed via Telegram, revealing a growing trend in modular and outsourced Android malware ecosystems.
