Spoofed Google Translate App Sneakily Installs Monero Mining Malware on Over 1 Lakh PCs

This malware called the ‘Nitrokod’ has been created by a Turkey-related entity as a desktop application for Google Translate.

Advertisement
Written by Radhika Parashar, Edited by Richa Sharma | Updated: 1 September 2022 15:43 IST
Highlights
  • The malware installs Monero mining set-up
  • Monero uses PoW mining model
  • The controller of this campaign may get access to infected PCs

The Nitrokod malware has been in circulation since 2019

Photo Credit: Bloomberg

A crypto mining malware, disguised as a Google Translate app, has come to light recently for having forayed into thousands of computers. As per a study by Check Point Research (CPR), this malware called the ‘Nitrokod' has been created by a Turkey-related entity as a desktop application for Google Translate. Several people have ended up downloading this app on their PCs in the absence of Google's official desktop app for Translate services. This app, once installed, later establishes elaborate crypto mining operation set-up on the infected PCs.

Once the app is downloaded on a computer, the malware installation process is triggered via a scheduled task mechanism. Upon completion, this malware puts in place a sophisticated mining set-up for the Monero cryptocurrency, which is based on the energy-intensive proof-of-work (PoW) mining model.

Advertisement

This gives the controller of this campaign, hidden access to the infected computers to scam users and later damage the machines.

“After the malware is executed, it connects to its C&C server to get a configuration for the XMRig crypto miner and starts the mining activity. The software can be easily found through Google when users search ‘Google Translate Desktop download'. The applications are trojanised and contain a delayed mechanism to unleash a long multi-stage infection,” CPR said in its report.

As for now, PCs across at least eleven nations have been compromised via Nitrokod malware that has been in circulation since 2019.

Advertisement

CPR has posted updates and alerts about this crypto mining campaign on Twitter.

In recent times, the crypto sector has become a popular means for scamming among cyber criminals.

Advertisement

Scammers have been using the public trust on popular tech brands like LinkedIn, Twitter, and Google to fish out their victims and strike them.

Crypto scams via ‘unicode letters' as well as ‘honeypot accounts' have also increased in frequency in recent times, cyber researcher Serpent noted in his Twitter thread.

In the former, scammers replace URLs to legitimate sites with infected ones created by them. Characters in the infected URLs are made to look like the ones in the real links. Once the target enters the fake website and gives away their login information, their assets come closer to being under the control of the scammer, who eventually drains it off the wallet.

Advertisement


This week, we discuss Android 13 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy M17e 5G Debuts With 6,000mAh Battery at This Price in India
  2. Apple Launches AirPods Max 2 With New H2 Chip, Improved ANC: See Details
  3. Here's How Much the Poco X8 Pro Series Could Cost in India
  4. Nvidia Unveils DLSS 5 Graphics Upscaler, Faces Backlash Over 'AI Slop Filter'
  5. iQOO Z11x 5G With 7,200mAh Battery Goes on Sale in India: See Price, Offers
  6. iQOO Z11 Surfaces on Benchmarking Site Ahead of Its Launch in China
  7. Best Mobiles Under Rs. 25,000 in India
  8. Nvidia Brings NemoClaw as the Security Layer for OpenClaw Agents
  9. Oppo Find X9 Ultra Specifications Leaked in Detail Ahead of Global Launch
  10. Tecno Spark Go 3 Review: Last of the Sub-Rs. 10,000 Budget Phones?
  1. Lenovo Legion Phone Spotted in Leaked Live Images That Hint at Gaming Line Revival
  2. Vivo X300 Ultra, Vivo X300s Launch Date and Memory Configurations Leaked; Vivo Pad 6 Pro Might Tag Along
  3. Nvidia Unveils DLSS 5 Graphics Upscaler, Issues Clarification After Backlash Over 'AI Slop Filter'
  4. Samsung Galaxy M17e 5G Launched in India With 6,000mAh Battery, 50-Megapixel Camera: Price, Features
  5. Nvidia Introduces NemoClaw, an AI Stack to Make OpenClaw Agents More Secure
  6. Oppo Find X9 Ultra Specifications Leaked in Detail Ahead of Global Launch
  7. OnePlus 15, OnePlus 13s Receive Latest OxygenOS 16 Update in India With March 2026 Security Fixes
  8. Poco X8 Pro Series Price in India Leaked Alongside Storage Variants Hours Ahead of Launch
  9. Vivo, iQOO Smartphones to Get More Expensive in China as Component Prices Continue to Rise: Report
  10. iQOO Z11 With MediaTek Dimensity 8500 SoC Surfaces on Geekbench Ahead of China Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.