Skip to main content

Tag: android

113 articles

Person holds Android smartphone with blank screen in a neutral background.

ToxicPanda Malware Exploits VPN Permissions to Evade Google Play Security Checks

Meet ToxicPanda, a sneaky malware that's evolved to outsmart Google Play's security checks by exploiting VPN permissions and controlling device traffic. This cunning threat can now target nearly 350 apps and execute over 160 remote commands, putting your mobile security at risk.

Analyst 207
Technicians walk by rows of server racks and networking equipment in a modern network operations center.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities

Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Analyst 207
Smartphone on cluttered desk with blank screen in soft daylight.

Mobile Malware Attacks Decline, Banking Trojans Persist

Mobile malware attacks may be on the decline, but don't let your guard down - over 1.99 million mobile devices were still threatened by malware, adware, or unwanted software in the second quarter alone. Banking Trojans, in particular, remain a persistent threat, with over 93,000 malicious packages detected.

Analyst 207
Modern tech lab with empty workstations, spotlight on a lone laptop screen displaying a blurred interface.

Cybercriminals Exploit AI Safety Controls with Task-Splitting Technique

Cybercriminals are outsmarting AI safety controls with a clever task-splitting technique, allowing them to assemble malicious tools like DDoS software with ease. By breaking down bad code into tiny, harmless pieces, they're slipping past guardrails and wreaking havoc - as seen in a recent attack that took control of nearly 2,000 Android TVs.

Analyst 207
Darkened room with multiple screens and devices, individuals huddled around cluttered table with notes and papers.

BTMOB Malware Ecosystem Fractures as Resellers Exploit Source Code

The BTMOB malware ecosystem has shattered into a patchwork of fragmented offerings, morphing from a single, centrally operated service to a chaotic mix of official releases, private servers, and reseller panels. This dramatic shift comes after the source code was exploited, sending the once-coordinated operation into a tailspin.

Analyst 207
Smartphone on a cluttered desk with laptop and notepad in background.

Invisible Screen Text Exposes Android AI Agents to Code Injection Attacks

Researchers found that a simple payload could launch a code injection attack on four open-source Android agent frameworks, successfully executing commands on the host's system in every trial. This alarming vulnerability allows attackers to exploit AI agents by manipulating text on the screen, turning a harmless string into a malicious command.

Analyst 207
Smartphone on a neutral surface with blurred background and abstract screen pattern.

EU Orders Google to Open Android to Rival AI Assistants

Google is now required to open up Android to rival AI assistants, a move the company claims could compromise device security by giving external apps sensitive permissions. The European Commission's order, made under the Digital Markets Act, forces Google to grant third-party AI assistants access to Android sensors and system features.

Analyst 207
Dimly lit storefront at night with scattered neon signs and a blank smartphone screen on a cluttered counter.

RedWing Malware Targets Android Users with Bank Fraud as a Service

A new, ready-to-use bank-fraud tool called RedWing is being rented on Telegram, allowing even novice criminals to hijack Android users' phones and steal their banking information. This malicious kit is sold as a complete package, complete with step-by-step guides and how-to videos, making it alarmingly easy for scammers to get started.

Analyst 207
A dimly lit computer server room with idle equipment and monitors, focusing on a single unattended Linux terminal on a…

Linux Flaw Exposes Unprivileged Users to Root Access

A newly discovered Linux flaw, CVE-2026-46242, allows ordinary users to gain root access to a machine, and even Android devices are vulnerable. This alarming vulnerability, known as Bad Epoll, can be exploited with ease, but thankfully, a working fix is now available.

Analyst 207
Home network setup with disrupted connections and erratic router lights.

FBI and Google Disrupt NetNut Proxy Network Used by Cyber Threat Actors

In a major win for cybersecurity, the FBI and Google have joined forces to dismantle the notorious NetNut proxy network, a go-to tool for cyber threat actors. This disruption has significantly reduced the network's capacity, cutting the available pool of devices by millions.

Analyst 207
Formal courthouse interior with tall windows and neutral background.

EU Court Upholds $4.7 Billion Google Antitrust Fine

Google's last-ditch effort to overturn a $4.7 billion antitrust fine has been rejected by the EU's top court, affirming that the company's Android agreements did indeed stifle competition. The Court of Justice of the European Union dismissed Google's appeal, upholding the hefty penalty.

Analyst 207
Devices with blank screens sit on a table in a public area, surrounded by people in the background.

AirDrop and Quick Share Flaws Expose Devices to Local Attacks

Millions of devices are vulnerable to local attacks due to flaws in popular sharing services like AirDrop and Samsung Quick Share, discovered by researchers Arash Ale Ebrahim and Nils Ole Tippenhauer. They found six distinct flaws that can be exploited by nearby attackers to crash services or bypass security checks.

Analyst 207
Smartphone on a neutral surface with blurred screen, set against a cityscape background.

Google Tightens Android App Verification Rules Ahead of Sept. 30 Deadline

Get ready for a safer app experience on Android! As of September 30, 2026, Google will start enforcing developer verification, blocking installs of unverified apps on certified phones in Brazil, Indonesia, Singapore, and Thailand.

Analyst 207
Smartphone on a neutral surface with a blurred mobile app interface and a hint of a cityscape through a nearby window.

Microsoft 365 Android Apps Expose Account Tokens Due to Debug Flag Oversight

A single line of code, "setIsDebugMode(true)," inadvertently left in multiple Microsoft 365 Android apps, created a gaping security hole that allowed other apps on the same phone to access sensitive account tokens without user permission. This tiny oversight, discovered by Enclave's Yanir Tsarimi and Ofek Levin, exposed users to potential security risks.

Analyst 207
A smartphone with a blank screen sits on a clean, neutral surface in a softly blurred modern setting.

Google patches actively exploited Android zero-day flaw amid June security updates

Google just patched a high-severity Android flaw that's being actively exploited by hackers, allowing them to gain control of devices running Android 14 or later. The June security update fixes this zero-day vulnerability, along with 123 others, to keep your device safe.

Analyst 207
Modern bank lobby with customer service desk and banking terminals.

Malware Campaigns Target Windows, Android Users in Global Finance Sector

Global finance sector faces a double threat as malware campaigns target Windows and Android users, with attackers using clever tactics like hiding in trusted traffic and selling mobile RATs as turnkey services. Two recent campaigns, one using Grandoreiro malware in Portugal, Spain, and Mexico, and another using a new BTMOB trojan in Brazil, highlight the evolving threat landscape.

Analyst 207
Formal law enforcement setting with podium and documents in daylight.

Canada Arrests Suspect Tied to Kimwolf Botnet Operation

In a major breakthrough, Canadian authorities have arrested 23-year-old Jacob Butler, aka "Dort", for his alleged role as a key administrator of the notorious Kimwolf botnet operation, which infected over 2 million Android TV devices worldwide. The arrest marks a significant step in the fight against one of the most widespread distributed-denial-of-service (DDoS) botnets on record.

Analyst 207
Two smartphones on a table, displaying chat interfaces with a lock icon, set against a blurred cityscape background.

Google and Apple Roll Out Cross-Platform RCS Encryption

Big news for messaging security: Apple and Google have just launched a beta rollout of end-to-end encrypted RCS messaging, allowing for more secure conversations between iPhone and Android users worldwide. This update enables encryption by default, marked with a lock icon, and is available to users with supported carriers and devices.

Analyst 207
Two smartphones, an iPhone and an Android device, sit side by side on a clean surface with a modern background.

Apple and Google Boost Cross-Platform Messaging with End-to-End Encryption

Say goodbye to the green bubble blues! iPhone and Android users can now send end-to-end encrypted messages to each other, thanks to a game-changing collaboration between Apple and Google.

Analyst 207
Smartphone with blurred Google Play Store page on screen, surrounded by receipts on a neutral surface in a bright, everyday…

Fraudulent Call History Apps Drain Millions via 7.3M Play Store Downloads

Millions of Android users have been duped into downloading 28 fake call history apps from the Google Play Store, with over 7.3 million downloads recorded before they were finally removed. These apps, which promised access to call logs and more, actually delivered nothing but randomly generated data - and a hefty price tag.

Analyst 207
Laptop on a desk with Phone Link app open, smartphone nearby, in a home office setting with subtle network device hint.

CloudZ RAT Exploits Windows Phone Link for Credential Theft

Cyber attackers have cleverly exploited the Microsoft Phone Link feature to steal sensitive credentials and one-time passwords, all without needing to infect mobile devices with malware. By targeting this built-in Windows application, hackers can access synced phone data and extract valuable information.

Analyst 207
Brightly lit computer workstation with generic gaming peripherals and cables against a neutral background.

ScarCruft Expands Malware Arsenal with Multi-Platform BirdCall Backdoor

ScarCruft hackers have launched a sneaky attack on a popular video game platform, infecting both Windows and Android users with a new backdoor called BirdCall. The multi-platform threat has been targeting ethnic Koreans in China since late 2024, allowing hackers to gain unauthorized access.

Analyst 207
Dark cityscape with broken smartphone, credit card and lock on screen, and shadowy figure near public transit terminal with…

NGate Malware Exploits HandyPay App to Steal Android NFC Payment Data

Malicious NGate malware has been discovered hiding inside a fake version of the HandyPay app, putting Android users' NFC payment data at risk. This sneaky malware exploits a trusted payments tool to steal sensitive information, leaving users vulnerable to financial theft.

Analyst 207
Darkened office with eerie shadows, a laptop displaying ominous code and a cracked smartphone, with a ghostly figure in the…

Malware Campaigns Exploit Trusted Channels for Internal Access

Instead of smashing down the front door, attackers are now sneaking in by exploiting trusted channels and misdirecting trust - a subtle yet effective tactic that's leaving defenders, regulators, and users scrambling to respond. This quiet approach to breaching security is a growing concern, with multiple incidents revealing a common pattern of adversaries using third-party components to gain internal access.

Analyst 207