Advertisement
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are actively targeting financial users globally, stealing credentials and data.
Android Car Head Units Infected by MoYu Proxy Botnet Malware
A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.
Android Malware WindRelay & SpyNote: NFC Relay for Loan Fraud
A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…
NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off
A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.
Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance
Runtime Rebel analyzes Iranian-nexus TAG-182's use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.
Advertisement
Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service
Researchers link the massive Popa Android botnet to NetNut, a residential proxy provider. The botnet exploits millions of TV boxes for fraud and scraping.
Rokarolla Android Malware Targets 217 Financial Apps
New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.
NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks
Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.
Asin Android Spyware Targets Arabic Users via Fake War Maps
ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.
BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover
BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.
Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users
Analysis of Grandoreiro and BTMOB malware campaigns targeting financial sectors in Spain, Portugal, and Latin America through Windows and Android platforms.
TrickMo Android Trojan Uses TON Blockchain for Covert C2
TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.
Telegram Mini Apps Exploited for Crypto Scams and Malware Delivery
Threat actors are weaponizing Telegram Mini Apps to distribute Android malware and deploy sophisticated crypto drainers via TON blockchain exploits.
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.
Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse
Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.
Perseus Android Banking Malware Targets Notes Apps for Data Theft
Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.