-
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,0…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into rogue contactless-card readers and enable real-time, card-present fraud. Group-IB’s investigation …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


