Tag

Android Malware

All articles tagged with #android malware

RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims
cybersecurity7 days ago

RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims

Security researchers have identified RatHat, an Android banking trojan that leverages Google’s Gemini AI to navigate device interfaces and prioritize victims with high bank balances. The malware spreads via SMS phishing and malicious ads, requiring users to sideload apps and grant Accessibility permissions. Once installed, it exploits Wireless Debugging to gain shell-level access, intercepts two-factor authentication codes, and reconstructs PINs by analyzing touch coordinates. Cleafy reports that the malware’s control console uses AI to sort victims by financial value, while Zimperium notes its persistence mechanisms make removal difficult without a factory reset.

RemControl and RatHat: AI-Driven Android Malware Targets Banking Users in Europe and Canada
cybersecurity14 days ago

RemControl and RatHat: AI-Driven Android Malware Targets Banking Users in Europe and Canada

Two new Android malware strains, RemControl and RatHat, are exploiting AI and accessibility permissions to steal banking credentials. RemControl, a malware-as-a-service platform, targets users in Europe and Canada via fake TVTap app downloads, while RatHat uses AI to navigate device interfaces and capture touch inputs for PINs.

RedHook variant weaponizes Wireless ADB to gain shell control on Android
technology-security2 months ago

RedHook variant weaponizes Wireless ADB to gain shell control on Android

A new RedHook Android malware variant abuses Wireless ADB to obtain shell-level privileges without a PC by tricking victims into granting Accessibility permissions and using Shizuku to run privileged commands. It effectively turns the phone into its own ADB client (via 127.0.0.1), enabling 53 commands including screen streaming, input simulation, app install/uninstall, data theft, overlays, and even camera access, all without device rooting. The malware uses multiple persistence methods (silent audio, WakeLocks, dual services, watchdog, boot autostart, and oom_score_adj) and is distributed via social engineering that impersonates government or financial institutions to push fake Google Play sites. Users are advised to only install from Google Play, scrutinize permissions, and keep Play Protect enabled.

Mirax Android RAT Turns Phones Into SOCKS5 Proxies via Meta Ads
cybersecurity5 months ago

Mirax Android RAT Turns Phones Into SOCKS5 Proxies via Meta Ads

A new Android remote access Trojan named Mirax blends traditional RAT capabilities with a residential SOCKS5 proxy feature, allowing attackers to route traffic through infected devices. Campaigns reach about 220,000 accounts on Facebook, Instagram, Messenger, and Threads via Meta ads promoting a malware dropper, with Mirax offered as a MaaS to a small, Russia-focused affiliate network. Once installed, it can capture data, render fake overlays for credential theft, and maintain multiple C2 channels (WebSockets on ports 8443, 8444, and 8445) for remote control, streaming, exfiltration, and proxy deployment. Distribution uses GitHub-hosted droppers and two crypters (Virbox and Golden Crypt) with anti-analysis checks, reflecting a trend of combining RAT functionality with proxy networks for monetization and broader reach.

Perseus Android malware hunts secrets in notes, gains full device control
technology6 months ago

Perseus Android malware hunts secrets in notes, gains full device control

A new Android banking Trojan named Perseus disguises itself as IPTV apps to distribute via unofficial stores. It uses Android Accessibility Services to scan and extract sensitive data from note apps (Google Keep, Samsung Notes, Evernote, OneNote, etc.), including passwords and recovery phrases, enabling full remote control over infected devices (screenshots, overlay attacks, keylogging, app launches, and more). The malware evades analysis with anti‑analysis checks and a “suspicion score” to decide whether to proceed. It primarily targets Turkish and Italian financial institutions and crypto apps. Users are advised to avoid sideloading APKs, only use Google Play, and keep Play Protect enabled.

Phishing PWA Poses as Google Security Page to Steal OTPs and Proxy Victims’ Traffic
technology7 months ago

Phishing PWA Poses as Google Security Page to Steal OTPs and Proxy Victims’ Traffic

A phishing campaign disguises a fake Google Security page as a Progressive Web App to trick users into granting permissions. The malicious PWA can exfiltrate one-time passwords, clipboard contents, contacts, and GPS data, and can proxy the victim’s browser traffic and scan internal networks via a WebSocket relay. An Android APK is also distributed to extend access with keystroke capture and device admin persistence. The attack relies on social engineering, not exploiting a vulnerability. Google says security checks aren’t done via pop-ups; remove the PWA and revoke device admin rights following Malwarebytes’ removal guidance.

PromptSpy uses GenAI to persist on Android via AI-guided UI manipulation
security7 months ago

PromptSpy uses GenAI to persist on Android via AI-guided UI manipulation

ESET researchers uncovered PromptSpy, the first known Android malware to use generative AI (Google Gemini) to drive UI-level actions for persistence. By feeding Gemini an XML snapshot of the current screen, the AI returns step-by-step tap instructions to keep the app in the recent apps list, while a built-in VNC module provides remote access. The malware also exploits Accessibility Services, overlays to hinder uninstallation, and can capture lockscreen data and screen video. Distribution appears tied to Argentina via a banking/phishing site; no Google Play presence. This example shows how AI can make Android threats more adaptive and harder to defeat.

Keenadu: A firmware-level Android tablet backdoor hidden in signed OTA updates
technology7 months ago

Keenadu: A firmware-level Android tablet backdoor hidden in signed OTA updates

A new Android backdoor named Keenadu is embedded in tablet firmware and distributed via signed OTA updates, enabling attackers to remotely control devices, hijack browsers, monetize app installs, and exfiltrate data through a multi-stage loader that operates across all apps. It also spreads via trojanized apps on Google Play, with Google removing three related apps and Play Protect offering protection. About 13,700 users have been affected worldwide, with clusters in Russia, Japan, Germany, Brazil, and the Netherlands. Keenadu targets core Android components (libandroid_runtime.so, Zygote, system_server) to bypass sandboxing, allowing payloads to be delivered per targeted app and enabling broad control over the device.

Android Malware Steals Card Details and Drains Bank Accounts
technology11 months ago

Android Malware Steals Card Details and Drains Bank Accounts

A new Android malware called NGate has been discovered that can steal debit card details and PINs via NFC technology, allowing hackers to make ATM withdrawals without physical card theft. The malware is spread through social engineering tactics like phishing and fake apps, emphasizing the importance of downloading apps only from trusted sources and being cautious with personal information. Protecting devices with antivirus software and staying vigilant against scams are crucial to prevent such attacks.

Android malware mimics human typing to evade detection and steal money
technology11 months ago

Android malware mimics human typing to evade detection and steal money

A new Android malware called Herodotus is designed to steal banking credentials by mimicking human typing and overlaying fake login screens, with active campaigns in Italy and Brazil, and is sold as a service on underground forums. It uses sophisticated techniques to evade detection, including random delays in keystrokes, and can hijack input and steal sensitive data, posing a significant threat to mobile banking security.

Android Malware Evolves: From Banking Trojans to Advanced Spyware and Crypto-Stealers
cybersecurity1 year ago

Android Malware Evolves: From Banking Trojans to Advanced Spyware and Crypto-Stealers

Cybersecurity researchers report a shift in Android malware, with dropper apps now delivering SMS stealers and spyware instead of just banking trojans, using sophisticated methods to evade Google Play Protect and targeting users in Asia and Europe through malicious apps and ads, highlighting ongoing challenges in mobile security.

FBI Warns of BADBOX 2.0 Android Malware Impacting Millions
technology1 year ago

FBI Warns of BADBOX 2.0 Android Malware Impacting Millions

The FBI warns that the BADBOX 2.0 malware has infected over 1 million consumer IoT devices, mainly Android-based smart TVs and streaming devices, turning them into residential proxies for malicious activities like ad fraud and credential stuffing. Despite disruptions, the botnet continues to grow globally, with devices from China shipped worldwide, and consumers are advised to monitor their devices and avoid unofficial app stores.

FakeCall Malware Exploits Androids for Banking Scams
mobile-security-financial-fraud1 year ago

FakeCall Malware Exploits Androids for Banking Scams

A new variant of the FakeCall Android malware has been discovered, using voice phishing techniques to deceive users into divulging personal information. This sophisticated malware can intercept and hijack calls, redirecting them to fraudulent numbers controlled by attackers, while mimicking legitimate banking interfaces. It exploits accessibility services to gain control over devices, capturing sensitive data and performing unauthorized actions. The malware's evolution highlights ongoing challenges in mobile security, despite efforts to enhance defenses against such threats.