<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Android Malware</title><description>Cybersecurity articles tagged #Android Malware on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active</title><link>https://runtimerebel.com/blog/banking-trojans-manic-grandoreiro-toxicpanda-2-0-active</link><guid isPermaLink="true">https://runtimerebel.com/blog/banking-trojans-manic-grandoreiro-toxicpanda-2-0-active</guid><description>New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are actively targeting financial users globally, stealing credentials and data.</description><pubDate>Sat, 22 Aug 2026 16:14:50 GMT</pubDate><category>Banking Trojan</category><category>Grandoreiro</category><category>Android Malware</category><category>Manic</category><category>ToxicPanda</category></item><item><title>Android Car Head Units Infected by MoYu Proxy Botnet Malware</title><link>https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</guid><description>A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.</description><pubDate>Sat, 22 Aug 2026 16:13:49 GMT</pubDate><category>Android Malware</category><category>Proxy Botnet</category><category>Supply Chain Attack</category><category>Ad Fraud</category><category>MoYu Group</category></item><item><title>Android Malware WindRelay &amp; SpyNote: NFC Relay for Loan Fraud</title><link>https://runtimerebel.com/blog/android-malware-windrelay-spynote-nfc-relay-for-loan-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-malware-windrelay-spynote-nfc-relay-for-loan-fraud</guid><description>A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.</description><pubDate>Thu, 13 Aug 2026 09:03:15 GMT</pubDate><category>Android Malware</category><category>Social Engineering</category><category>Financial Fraud</category><category>WindRelay</category><category>SpyNote</category></item><item><title>Flying Eagle Mobile RAT Builder: China&apos;s Infostealer-as-a-Service</title><link>https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</guid><description>Analysis of the &apos;Flying Eagle&apos; mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…</description><pubDate>Thu, 30 Jul 2026 02:32:07 GMT</pubDate><category>Flying Eagle</category><category>Mobile RAT</category><category>Android Malware</category><category>Infostealer</category><category>Malware as a Service</category><category>Financial Fraud</category><category>China</category></item><item><title>NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off</title><link>https://runtimerebel.com/blog/netnut-residential-proxy-disrupted-2m-android-devices-cut-off</link><guid isPermaLink="true">https://runtimerebel.com/blog/netnut-residential-proxy-disrupted-2m-android-devices-cut-off</guid><description>A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.</description><pubDate>Sat, 04 Jul 2026 06:48:52 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Android Malware</category><category>Botnet</category><category>Proxy Disruption</category><category>Smart TV Security</category></item><item><title>Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance</title><link>https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</guid><description>Runtime Rebel analyzes Iranian-nexus TAG-182&apos;s use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.</description><pubDate>Thu, 02 Jul 2026 07:41:52 GMT</pubDate><category>TAG 182</category><category>MarkiRAT</category><category>Iran</category><category>Cyber Surveillance</category><category>Android Malware</category><category>Mobile Threat</category><category>APT</category></item><item><title>Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service</title><link>https://runtimerebel.com/blog/popa-botnet-linked-to-alarum-technologies-netnut-proxy-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/popa-botnet-linked-to-alarum-technologies-netnut-proxy-service</guid><description>Researchers link the massive Popa Android botnet to NetNut, a residential proxy provider. The botnet exploits millions of TV boxes for fraud and scraping.</description><pubDate>Fri, 19 Jun 2026 09:47:40 GMT</pubDate><category>Popa Botnet</category><category>NetNut</category><category>Alarum Technologies</category><category>Android Malware</category><category>Residential Proxy</category><category>Ad Fraud</category></item><item><title>Rokarolla Android Malware Targets 217 Financial Apps</title><link>https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</guid><description>New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.</description><pubDate>Tue, 16 Jun 2026 21:08:26 GMT</pubDate><category>Rokarolla</category><category>Android Malware</category><category>Banking Trojan</category><category>Mobile Security</category><category>Financial Services</category><category>Overlay Attack</category></item><item><title>NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks</title><link>https://runtimerebel.com/blog/nfcshare-malware-github-spoofing-leads-to-nfc-relay-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/nfcshare-malware-github-spoofing-leads-to-nfc-relay-attacks</guid><description>Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.</description><pubDate>Tue, 09 Jun 2026 00:56:06 GMT</pubDate><category>Android Malware</category><category>Nfcshare</category><category>Ngate</category><category>Github Threats</category><category>Mobile Banking</category></item><item><title>Asin Android Spyware Targets Arabic Users via Fake War Maps</title><link>https://runtimerebel.com/blog/asin-android-spyware-targets-arabic-users-via-fake-war-maps</link><guid isPermaLink="true">https://runtimerebel.com/blog/asin-android-spyware-targets-arabic-users-via-fake-war-maps</guid><description>ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.</description><pubDate>Fri, 05 Jun 2026 16:54:06 GMT</pubDate><category>Asin Spyware</category><category>Android Malware</category><category>Middle East Threats</category><category>ESET</category></item><item><title>BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover</title><link>https://runtimerebel.com/blog/btmob-android-malware-analyzing-phishing-driven-full-device-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/btmob-android-malware-analyzing-phishing-driven-full-device-takeover</guid><description>BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.</description><pubDate>Thu, 28 May 2026 13:26:29 GMT</pubDate><category>BTMOB</category><category>Android Malware</category><category>Phishing</category><category>VNC</category><category>Financial Fraud</category><category>Mobile Security</category></item><item><title>Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users</title><link>https://runtimerebel.com/blog/grandoreiro-and-btmob-rat-campaigns-target-windows-and-android-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/grandoreiro-and-btmob-rat-campaigns-target-windows-and-android-users</guid><description>Analysis of Grandoreiro and BTMOB malware campaigns targeting financial sectors in Spain, Portugal, and Latin America through Windows and Android platforms.</description><pubDate>Wed, 27 May 2026 17:11:44 GMT</pubDate><category>Grandoreiro</category><category>BTMOB</category><category>Banking Trojan</category><category>Android Malware</category><category>ESET</category><category>WatchGuard</category></item><item><title>TrickMo Android Trojan Uses TON Blockchain for Covert C2</title><link>https://runtimerebel.com/blog/trickmo-android-trojan-uses-ton-blockchain-for-covert-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/trickmo-android-trojan-uses-ton-blockchain-for-covert-c2</guid><description>TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.</description><pubDate>Mon, 11 May 2026 09:18:04 GMT</pubDate><category>Trickmo</category><category>Android Malware</category><category>TON Blockchain</category><category>Banking Trojan</category><category>Fintech Threats</category></item><item><title>Telegram Mini Apps Exploited for Crypto Scams and Malware Delivery</title><link>https://runtimerebel.com/blog/telegram-mini-apps-exploited-for-crypto-scams-and-malware-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/telegram-mini-apps-exploited-for-crypto-scams-and-malware-delivery</guid><description>Threat actors are weaponizing Telegram Mini Apps to distribute Android malware and deploy sophisticated crypto drainers via TON blockchain exploits.</description><pubDate>Sun, 03 May 2026 16:20:23 GMT</pubDate><category>Telegram</category><category>Mini Apps</category><category>Android Malware</category><category>Crypto Scams</category><category>TON Blockchain</category><category>Phishing</category></item><item><title>NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil</title><link>https://runtimerebel.com/blog/ngate-android-malware-trojanized-handypay-targets-nfc-data-in-brazil</link><guid isPermaLink="true">https://runtimerebel.com/blog/ngate-android-malware-trojanized-handypay-targets-nfc-data-in-brazil</guid><description>Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.</description><pubDate>Tue, 21 Apr 2026 12:30:50 GMT</pubDate><category>Ngate</category><category>Android Malware</category><category>NFC Theft</category><category>HandyPay</category><category>Brazil Threats</category></item><item><title>Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse</title><link>https://runtimerebel.com/blog/mirax-rat-analysis-android-devices-targeted-for-proxy-node-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/mirax-rat-analysis-android-devices-targeted-for-proxy-node-abuse</guid><description>Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.</description><pubDate>Wed, 15 Apr 2026 12:30:33 GMT</pubDate><category>Mirax RAT</category><category>Android Malware</category><category>Proxy Botnet</category><category>Mobile Security</category></item><item><title>Perseus Android Banking Malware Targets Notes Apps for Data Theft</title><link>https://runtimerebel.com/blog/perseus-android-banking-malware-targets-notes-apps-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/perseus-android-banking-malware-targets-notes-apps-for-data-theft</guid><description>Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.</description><pubDate>Thu, 19 Mar 2026 16:24:30 GMT</pubDate><category>Perseus Malware</category><category>Android Malware</category><category>Banking Trojan</category><category>Cerberus</category><category>Financial Fraud</category></item></channel></rss>