Articles tagged "Android"

Found 47 articles

Actively Exploited

Researchers from Flare have examined the underground market for BTMOB, a type of Android malware. Their analysis revealed a complex network of resellers, vendors offering source code, and various customized versions of the malware being sold across different platforms. This fragmentation indicates that the malware operation has evolved significantly, with multiple players now involved in its distribution and refinement. The implications are serious, as this could lead to more widespread attacks on Android users, putting sensitive data at risk. Understanding this ecosystem is crucial for cybersecurity professionals who need to combat the increasing sophistication of mobile threats.

Read Original

The source code for the Flying Eagle Android remote access trojan (RAT) has been found circulating in criminal Telegram channels, raising concerns about potential exploitation. Researchers from Hunt.io and NetAskari traced this malicious framework to 170 internet servers, linking it to a deceptive application masquerading as a Chinese Public Security service. This application targets Android users in China and reportedly supports functionalities related to payment passwords. The distribution of this RAT poses significant risks to users, as it can enable attackers to gain unauthorized control over devices, potentially leading to data theft and financial fraud. Users in China, particularly those using the compromised app, should be vigilant and avoid downloading unverified applications to protect their personal information.

Read Original
Critical
igloohome Smart Lock Mobile Application

All CISA Advisories

A vulnerability in the igloohome Smart Lock Mobile Application has been discovered, affecting version 3.2.3 and earlier. This flaw, identified as CVE-2026-16581, allows unauthorized access to backend services due to sensitive information being included in the application's source code. As a result, attackers could exploit this weakness to access functionality that should be protected by authentication measures. igloohome has addressed the issue by enhancing access controls to prevent unauthorized requests. Users are advised to ensure they are using the latest version of the app to mitigate risks.

Read Original
Critical
Johnson Controls XAAP Android

All CISA Advisories

A vulnerability has been identified in the Johnson Controls XAAP Android application, specifically in versions prior to 1.53. This flaw allows sensitive data to be stored in cleartext on devices, making it accessible to attackers who have physical access or can exploit another vulnerability on the device. The issue does not require network access and poses risks to users worldwide, particularly in critical manufacturing sectors. Johnson Controls advises users to upgrade to version 1.53 or later to mitigate this risk, and recommends implementing additional security measures such as restricting physical access, enabling device encryption, and using Mobile Device Management solutions to enforce security policies. Currently, there have been no reports of this vulnerability being actively exploited in the wild.

Read Original

Lookout has introduced a new tool aimed at assessing the security of mobile applications on both Android and iOS platforms. This tool works by analyzing the apps at the binary level, producing a software bill of materials that lists the components used in each application. It then cross-references these components with existing vulnerability databases and threat intelligence feeds to identify potential security risks. This development is significant as it helps developers and organizations understand the exposure risks associated with the software they deploy, which is crucial for protecting user data and maintaining application integrity. By providing insights into vulnerabilities, Lookout's tool aims to enhance the overall security posture of mobile applications.

Read Original
Actively Exploited

A new version of the RedHook malware for Android has been discovered using a technique that exploits the Wireless Debugging feature, known as Wireless ADB. This allows attackers to gain shell-level access to devices without needing a physical connection to a computer. This development raises concerns because it can enable unauthorized control over affected devices, putting personal data and privacy at risk. Users of Android devices, especially those with Wireless ADB enabled, should be particularly vigilant. Researchers emphasize the need for users to disable this feature when not in use to mitigate potential risks.

Read Original

Android has introduced a new security feature designed to detect fake cell towers, which can pose significant risks to user data. This feature alerts users if their device connects to an untrusted network, helping to safeguard personal information from potential interception. However, users need to enable this feature manually to benefit from the protection it offers. The rise of fake cell towers, often employed by attackers to eavesdrop on communications, makes this an important tool for Android users. By activating this feature, users can enhance their security and reduce the likelihood of falling victim to data breaches or privacy invasions.

Read Original

A new malware called RustDuck is actively hijacking various devices, including home routers, IP cameras, Android boxes, and poorly secured servers. The malware operates in two stages and connects these compromised devices into a botnet designed to launch Distributed Denial of Service (DDoS) attacks, effectively taking websites and online services offline. Researchers from QiAnXin's XLab have been monitoring RustDuck since February 2026 and note that its rapid evolution is particularly concerning. This highlights the vulnerability of consumer devices and poorly secured servers, which can be easily exploited by attackers. Users and organizations need to ensure their devices are secured to prevent becoming part of such a botnet.

Read Original
Actively Exploited

The latest Malware newsletter from Security Affairs discusses several significant cybersecurity incidents affecting a wide range of sectors. Notably, a supply chain attack on OptinMonster has compromised 1.2 million websites, raising concerns about the security of third-party services. Additionally, a China-linked threat actor has targeted both public and private medical organizations, focusing on areas like artificial intelligence and national defense research. Another piece highlights the Rokarolla malware, which is designed to steal banking information from Android devices. These incidents underscore the ongoing risks faced by organizations and individuals alike, as attackers increasingly exploit vulnerabilities across various sectors.

Read Original
Actively Exploited

A new Android banking trojan named Rokarolla has emerged, targeting 217 banking and cryptocurrency applications. This malware operates with a sophisticated toolkit, utilizing 137 different commands to carry out its operations. Users of affected apps may be at risk of having their sensitive financial information compromised. As cybercriminals continue to develop more advanced tactics, it's crucial for users to stay vigilant and ensure they have proper security measures in place. The rise of such malware highlights the ongoing threat to mobile banking and cryptocurrency platforms, making it essential for both users and developers to prioritize security.

Read Original

Recent reports from WatchGuard and ESET reveal two banking trojan campaigns targeting users in Latin America and Europe. The Grandoreiro malware is aimed at Windows devices, while the BTMOB RAT is designed for Android users. These campaigns specifically target companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil. The malware's ability to siphon sensitive financial information poses a significant risk to both businesses and individual users. As cybercriminals continue to adapt their tactics, it's crucial for users to remain vigilant and implement security measures to protect their devices and data.

Read Original

A new malware campaign named 'Premium Deception' has been discovered, using 250 fake Android apps to trick users into signing up for paid services without their consent. Researchers found that these apps, which masquerade as legitimate tools and games, charge users covertly, often leading to unexpected fees in their accounts. This campaign affects a wide range of Android users, particularly those who download apps from unofficial sources or third-party app stores. It's a reminder for users to be cautious about app permissions and to download software only from trusted platforms. The incident emphasizes the ongoing risks of mobile malware and the need for better awareness among users about app security.

Read Original
Actively Exploited

Researchers at ThreatFabric have identified a new variant of the TrickMo Android banking trojan, which is now routing its command and control (C2) traffic through The Open Network (TON). This change in infrastructure allows the malware to operate more stealthily, making it harder for security measures to detect and block its activities. The TrickMo trojan primarily targets Android devices, aiming to steal sensitive banking information from users. This development is concerning because it indicates that attackers are adapting their strategies to evade detection, which could lead to increased financial fraud. Users of Android devices, particularly those who engage in online banking, need to be vigilant and take precautions to protect their information.

Read Original

Google has introduced an initiative called Binary Transparency for Android to combat supply chain attacks. This public ledger ensures that the Google apps installed on devices are authentic and have not been tampered with. This move builds on the Pixel Binary Transparency feature that was launched in October 2021. The goal is to protect users by confirming that the applications they are using are exactly what Google intended to distribute. This is particularly important as supply chain attacks have become more common, posing risks to the integrity of software on mobile devices.

Read Original

A serious vulnerability, identified as CVE-2026-0073, has been discovered in the Android System component. This flaw allows attackers to execute remote code without any user interaction, posing a significant risk to devices running affected versions of Android. Users of Android devices should be particularly cautious, as this vulnerability could lead to unauthorized access and control over their devices. The potential for exploitation is high, making it crucial for users to apply the latest security updates. Android's security team has addressed this issue by releasing a patch to fix the vulnerability, and all users are encouraged to update their devices promptly to mitigate any risks.

Read Original
Page 1 of 4Next