Skip to main content
← All Articles

Tag

#Android Malware

17 articles

Advertisement

HIGH
Malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are actively targeting financial users globally, stealing credentials and data.

Runtime Rebel Intel
5 min read · Aug 22, 2026
HIGH
Supply Chain

Android Car Head Units Infected by MoYu Proxy Botnet Malware

A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.

Runtime Rebel Intel
4 min read · Aug 22, 2026
HIGH
Malware

Android Malware WindRelay & SpyNote: NFC Relay for Loan Fraud

A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.

Runtime Rebel Intel
4 min read · Aug 13, 2026
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
HIGH
Malware

Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service

Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…

Runtime Rebel Intel
4 min read · Jul 30, 2026
HIGH
Threat Intel

NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off

A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.

Runtime Rebel Intel
5 min read · Jul 4, 2026
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
HIGH
Threat Intel

Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance

Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.

Runtime Rebel Intel
5 min read · Jul 2, 2026

Advertisement

MEDIUM
Threat Intel

Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service

Researchers link the massive Popa Android botnet to NetNut, a residential proxy provider. The botnet exploits millions of TV boxes for fraud and scraping.

Runtime Rebel Intel
4 min read · Jun 19, 2026
HIGH
Malware

Rokarolla Android Malware Targets 217 Financial Apps

New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.

Runtime Rebel Intel
4 min read · Jun 16, 2026
HIGH
Malware

NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks

Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.

Runtime Rebel Intel
3 min read · Jun 9, 2026
Asin Android Spyware Targets Arabic Users via Fake War Maps
HIGH
Malware

Asin Android Spyware Targets Arabic Users via Fake War Maps

ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.

Runtime Rebel Intel
4 min read · Jun 5, 2026
HIGH
Malware

BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover

BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.

Runtime Rebel Intel
3 min read · May 28, 2026
Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users
HIGH
Threat Intel

Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users

Analysis of Grandoreiro and BTMOB malware campaigns targeting financial sectors in Spain, Portugal, and Latin America through Windows and Android platforms.

Runtime Rebel Intel
4 min read · May 27, 2026
HIGH
Malware

TrickMo Android Trojan Uses TON Blockchain for Covert C2

TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.

Runtime Rebel Intel
3 min read · May 11, 2026
HIGH
Threat Intel

Telegram Mini Apps Exploited for Crypto Scams and Malware Delivery

Threat actors are weaponizing Telegram Mini Apps to distribute Android malware and deploy sophisticated crypto drainers via TON blockchain exploits.

Runtime Rebel Intel
4 min read · May 3, 2026
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
HIGH
Malware

NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil

Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Malware

Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse

Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Perseus Android Banking Malware Targets Notes Apps for Data Theft
HIGH
Malware

Perseus Android Banking Malware Targets Notes Apps for Data Theft

Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.

Runtime Rebel Intel
3 min read · Mar 19, 2026