Tag: android
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware/
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Car Infotainment Malware Builds Criminal Proxy Botnet
DoFun Software Updates Exploited to Infect Android Head Units. Attackers are exploiting legitimate software updates to infect Android-based car infotainment systems, or head units, turning them into reverse proxies. Kaspersky linked the malware campaign to the MoYu Group, a threat actor linked to BADBOX and BADBOX 2.0. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652
-
Android Car Systems Infected With Malware Through Software Updates
Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-android-car-malware-software-update-botnet/
-
ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps
ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-toxicpanda-2-android-malware-349-financial-apps/
-
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys…
-
ToxicPanda 2.0 can take over your Android phone and banking apps
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps/
-
ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users’ financial applications at risk. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
-
ToxicPanda 2.0 Targets 349 Financial Apps and Steals Android Lock Credentials
ToxicPanda 2.0 is going after Android users in 16 countries, stealing banking and unlock credentials while taking control of devices through Wireless Debugging. First seen on hackread.com Jump to article: hackread.com/toxicpanda-2-0-app-steals-android-lock-credentials/
-
Hackers infecting Android car systems to build proxy botnet
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet. First seen on therecord.media Jump to article: therecord.media/android-botnet-china-hackers
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/android-malware-car-head-unit-badbox/
-
Botnetz aus Autos: Fahrzeug-Infotainmentsysteme mit Malware infiziert
Forscher haben eine Android-Malware entdeckt, die über eine Firmware-Updatefunktion in Infotainmentsysteme von Fahrzeugen eingeschleust wurde. First seen on golem.de Jump to article: www.golem.de/news/botnetz-aus-autos-fahrzeug-infotainmentsysteme-mit-malware-infiziert-2608-212212.html
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/
-
Security Affairs newsletter Round 591 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units…
-
New malware targets Android car head units for ad fraud and botnet creation
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-targets-android-car-head-units-for-ad-fraud-and-botnet-creation
-
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions…
-
Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait
Google’s new Android verification flow adds a 24-hour wait for apps from unverified developers as broader identity checks approach. The post Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-android-sideloading-24-hour-wait/
-
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
-
Neue Android-Malware kombiniert Fernzugriff und NFC für Kontodiebstahl in Echtzeit
First seen on t3n.de Jump to article: t3n.de/news/android-malware-nfc-betrug-spynote-windrelay-1759120/
-
Malware Hijacks Android Car Head Units
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but making zero effort to disguise itself as…
-
New Manic Android Malware Uses Offline Networks to Drain Bank Accounts
Manic Android malware steals banking credentials and can relay stolen data through nearby infected phones, complicating traditional device isolation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…
-
Unisoc-Modemfirmware ermöglicht vollen Android-Kernel-Zugriff über Videoanruf
SSD Secure Disclosure zeigt, wie sich per VoLTE-Videoanruf voller Android-Kernel-Zugriff erlangen lässt, ein Patch fehlt bislang. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/android-kernel-zugriff
-
Malware-Kampagne gegen Fahrzeug-Headunits des Herstellers DoFun
Kaspersky-Experten haben eine neuartige Android-Malware entdeckt, die gezielt Fahrzeug-Headunits des Herstellers DoFun angreift. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-kampagne-dofun
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
New Android banking Trojan ToxicPanda 2.0 expands victim targeting
First seen on scworld.com Jump to article: www.scworld.com/brief/new-android-banking-trojan-toxicpanda-2-0-expands-victim-targeting
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…

