Skip to content

Crypto malware impersonating Google Translate app infects thousands of PCs

Crypto malware impersonating Google Translate app infects thousands of PCs

Malicious software designed to mine cryptocurrency has been spreading across hundreds of devices under the appearance of a Google Translate app.

The malicious software, referred to as “Nitokod,” was designed as a desktop program for Google Translate and was built by an organization located in Turkey, according to Check Point Research (CPR) on August 29.

In the lack of an official desktop client for Google’s Translate services, a large number of Google users have downloaded this program on their computers. When this program is installed on a smartphone, it immediately begins setting up a sophisticated cryptocurrency mining business on that device. 

Following the downloading of this malicious application, the process of installing malware is initiated via the use of a scheduled task mechanism. In a later stage, this malicious software installs a complex mining rig for the Monero (XMR) cryptocurrency.

Infection chain. Source: Check Point

Mining software uses Proof of Work

The mining software is based on the Proof of Work (PoW) mining concept, which consumes a significant amount of electricity. As a result of this, it gives the controller of this campaign covert access to the computers that have been infected, allowing them to scam people and subsequently cause harm to the systems.

The CPR report claims: “After the malware is executed, it connects to its C&C server to get a configuration for the XMRig crypto miner and starts the mining activity. The software can be easily found through Google when users search ‘Google Translate Desktop download’. The applications are trojanised and contain a delayed mechanism to unleash a long multi-stage infection.”

According to reports, Nitrokod malware has affected machines in at least 11 countries since its distribution in 2019. CPR has also tweeted updates and warnings regarding the crypto mining effort. 

As per Zscaler Threatlabz, the Joker virus, another malware, infected 50 apps on the Google Play Store earlier this year in a similar approach. They were quickly deleted from Google’s app store. According to the Zscaler ThreatLabz team, the Joker, Facestealer, and Coper malware families were discovered to be propagating via applications. 

When the ThreatLabz team promptly informed the Google Android Security team of these newly identified hazards, the malicious applications were quickly removed from the Google Play Store.

However, even though many people in crypto are anxious about reports about possible scams, a recent study has shown that cryptocurrency scam revenue fell 65% and has been decreasing.

Best Crypto Exchange for Intermediate Traders and Investors

  • Invest in 70+ cryptocurrencies and 3,000+ other assets including stocks and precious metals.

  • 0% commission on stocks - buy in bulk or just a fraction from as little as $10. Other fees apply. For more information, visit

  • Copy top-performing traders in real time, automatically.

  • eToro USA is registered with FINRA for securities trading.

30+ million Users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. eToro USA LLC does not offer CFDs, only real Crypto assets available. Don’t invest unless you’re prepared to lose all the money you invest.

Read Next:

Weekly Finance Digest

By subscribing you agree with Finbold T&C’s & Privacy Policy

Related posts

Disclaimer: The information on this website is for general informational and educational purposes only and does not constitute financial, legal, tax, or investment advice. This site does not make any financial promotions, and all content is strictly informational. By using this site, you agree to our full disclaimer and terms of use. For more information, please read our complete Global Disclaimer.