Tag: android
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167 remote commands and expands its targeting footprint globally.Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. First…
-
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
-
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/
-
Android 17 QPR2 Beta 3: Google Adds Customization and New Scam Defenses
Android 17 QPR2 Beta 3 adds Pixel customization tools, call-forwarding scam protections, and experimental cellular security features. The post Android 17 QPR2 Beta 3: Google Adds Customization and New Scam Defenses appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-17-qpr2-beta-3-scam-protection/
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
AndroidKombination beantragt Kredite und leitet Daten weiter
Group-IB hat die Android-Malware WindRelay dokumentiert, die zusammen mit SpyNote Smartphones in gefälschte Kartenlesegeräte verwandelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/android-malware-kredite
-
New Unisoc modem flaw allows Android kernel access
First seen on scworld.com Jump to article: www.scworld.com/brief/new-unisoc-modem-flaw-allows-android-kernel-access
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Open Source: Android-Trojaner soll in Software von MG-Autos stecken
In einer Software-Dokumentation des chinesischen Herstellers MG taucht die Malware Teardroid auf. Das könnte jedoch ein Scan-Fehler sein. First seen on golem.de Jump to article: www.golem.de/news/open-source-android-trojaner-soll-in-software-von-mg-autos-stecken-2608-211759.html
-
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices
Samsung’s August 2026 Galaxy update fixes 56 Android and One UI security flaws, including critical vulnerabilities and clipboard access risks. The post Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-samsung-august-2026-security-update/
-
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices
Samsung’s August 2026 Galaxy update fixes 56 Android and One UI security flaws, including critical vulnerabilities and clipboard access risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-samsung-august-2026-galaxy-security-update/
-
OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app compatibility, device management, and long-term purchasing decisions. The post OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades appeared first on TechRepublic. First seen on techrepublic.com Jump…
-
Android app developers may be unwittingly sharing their users’ location data with advertisers
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/04/android-app-developers-may-be-unwittingly-sharing-their-users-location-data-with-advertisers/
-
Inside the Underground Business of the Android BTMOB RAT malware
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
-
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners’ home internet connections. First seen on hackread.com Jump to article: hackread.com/h96-android-tv-boxes-ad-fraud-residential-proxies/
-
Inside the Underground Business of BTMOB RAT
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
-
Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/product-showcase-guardio-mobile-security/
-
8 Best Password Managers (2026), Tested and Reviewed
Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers. First seen on wired.com Jump to article: www.wired.com/story/best-password-managers/
-
Fuyao operation uses Android TV boxes for ad fraud
First seen on scworld.com Jump to article: www.scworld.com/brief/fuyao-operation-uses-android-tv-boxes-for-ad-fraud
-
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators.Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019.The…
-
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/
-
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service and ended up mapping a sprawling criminal ecosystem built around a leaked Android RAT framework called…
-
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-play-age-signals-api-global-rollout/
-
Betrügerische Android-Apps schalten Werbung nach Anrufen
Tags: androidWerbeanzeigen nach Telefonaten: Betrügerische Android-Apps nutzen Berechtigungen aus, um unerwünschte Einblendungen auf Geräten zu erzeugen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/betrug-android-apps

