< ciso
brief />
Tag Banner

All news with #malware tag

810 articles · page 15 of 41

FBI: $20M+ Stolen in Surge of ATM Malware Attacks in 2025

🔔 The FBI says Americans lost more than $20 million last year amid a sharp increase in ATM 'jackpotting' attacks that use malware to force cash machines to dispense money. These attacks—often leveraging Ploutus—target the ATM's software layer (the XFS interface) to bypass bank authorization and trigger withdrawals without cards. The agency urged institutions to audit ATMs for unauthorized removable storage and validate system images to detect physical intrusion and malware staging.
read more →

FBI: 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost

💰 The FBI warned that 1,900 ATM jackpotting incidents have been reported since 2020, with 700 occurring in 2025 and losses exceeding $20 million last year. Threat actors deploy specialized malware such as Ploutus, often gaining physical access using generic keys to open ATM faces and then replacing or modifying hard drives to install code. The malware exploits the Windows OS and the ATM's XFS layer to issue dispenser commands directly, bypassing bank authorization and enabling rapid cash-outs across multiple ATM models. The FBI advised operators to strengthen physical protections, change default credentials, enforce device allowlisting, maintain logs, and configure automatic shutdowns when compromise indicators are detected.
read more →

PromptSpy: First Android Malware Using Generative AI

🛡️ ESET researcher Lukas Stefanko has identified PromptSpy, the first known Android malware to call a generative AI model at runtime, leveraging Google's Gemini to adapt persistence on different devices. The malware submits an XML dump of the current UI plus a chat prompt to Gemini, receives JSON-formatted instructions, and uses the Accessibility Service to pin the app in Recent Apps in a loop until confirmed. Its primary payload is a VNC-based spyware module that can capture PINs, record unlock patterns and screen activity, take screenshots, and report foreground apps. To block removal it overlays invisible UI elements over uninstall or permission controls; victims must reboot into Safe Mode to remove it.
read more →

PromptSpy Android Malware Leverages Gemini to Persist

🛡️ ESET researchers disclosed PromptSpy, the first Android malware observed to integrate Google's Gemini generative AI into its execution flow and achieve persistence. The malware assigns Gemini the persona of an 'Android automation assistant,' sends an XML dump of the current screen, and receives JSON step-by-step instructions that are executed via accessibility services. PromptSpy captures lockscreen data, records screens and video, deploys a VNC module for remote access, and blocks uninstallation using invisible overlays while communicating with a hard-coded C2.
read more →

Google Blocks Over 1.75 Million Play Store App Submissions

🛡️ Google says it blocked more than 1.75 million apps from being published on Google Play in 2025 and denied over 255,000 apps access to sensitive user data. The company also banned over 80,000 developer accounts and strengthened detection by integrating generative AI into its review process to identify evolving malicious patterns. Play Protect scanned an estimated 350 billion app instances daily and flagged over 27 million malicious sideloaded apps, while the Play Integrity API processed more than 20 billion checks per day.
read more →

Google Play 2025: Strengthening App Ecosystem Security

🔒 In 2025 Google deployed advanced AI-powered defenses across Google Play to stop apps that cause real-world harm, preventing over 1.75 million policy-violating apps from being published and banning more than 80,000 malicious developer accounts. We expanded Google Play Protect to scan over 350 billion Android apps daily and rolled out real-time protections including in-call scam defenses. Together these measures strengthened the Play store and the broader Android ecosystem by prioritizing automated detection, rapid enforcement, and on-device user safety.
read more →

Remcos RAT gains real-time surveillance and evasion

🔍 Researchers at Point Wild have identified a Remcos RAT variant that shifts toward real-time espionage and enhanced evasion. The strain streams webcam footage and sends captured keystrokes directly to attacker-controlled servers while delivering modular DLL plugins on demand. It decrypts its C2 configuration only in memory, resolves Windows APIs dynamically to hinder static analysis and performs cleanup routines to remove logs, cookies and persistence artifacts. Defenders should watch for suspicious outbound connections and unauthorized registry changes.
read more →

Industrial-Scale Fake Coretax Apps Drive $2M Fraud

🔍 Group-IB uncovered a sophisticated campaign that impersonated Indonesia’s official Coretax service to distribute malicious Android APKs, causing an estimated $1.5m–$2m in losses nationwide. Attackers combined phishing sites, WhatsApp impersonation and vishing to coerce victims into installing RATs such as Gigabud.RAT and MMRat, enabling remote access and unauthorized banking transfers. The operation produced 996 phishing URLs, 228 new malware samples and used infrastructure that impersonated over 16 trusted brands, suggesting a scalable MaaS model.
read more →

PromptSpy: GenAI-driven Android malware abuses Gemini

🧠 ESET researchers have identified PromptSpy, the first known Android malware to integrate generative AI (Google's Gemini) into its execution flow. The malware sends serialized UI XML to Gemini and receives JSON-formatted tap, swipe, and long-press instructions to navigate device-specific interfaces. This enables robust persistence by programmatically locking the app in Recent Apps and deploying a VNC module for remote control and data exfiltration. Distribution appears limited and regionally focused, but the technique raises broader concerns about AI misuse.
read more →

Massiv Android Trojan Targets IPTV Users for DTO Attacks

🛡️ ThreatFabric has disclosed Massiv, a new Android trojan that impersonates IPTV apps to deliver device takeover (DTO) attacks aimed at financial theft. Distributed via SMS phishing droppers, Massiv abuses Android accessibility and MediaProjection APIs to stream screens, capture keystrokes and SMS, and deploy fake overlays that harvest banking credentials and KYC data. Operators have used stolen information to open accounts, launder money and remotely control infected devices while concealing malicious activity behind black-screen overlays.
read more →

Massiv Android banking malware disguises as IPTV app

🔒 A new Android banking trojan called Massiv is being distributed as a fake IPTV application to harvest credentials, perform keylogging, and seize remote control of infected devices. Researchers at ThreatFabric observed campaigns that targeted a Portuguese government app integrated with Chave Móvel Digital, enabling fraudsters to bypass KYC checks and open accounts in victims' names. Massiv supports live screen streaming via Android's MediaProjection API and a UI-tree mode using the Accessibility Service to extract interface elements, click controls, and bypass screen-capture protections.
read more →

AI platforms can be abused for stealthy malware communication

🛡️ Researchers at Check Point demonstrated that AI assistants with web browsing and URL-fetching capabilities can be abused as intermediaries for stealthy command-and-control (C2) communication. In their proof-of-concept, malware used Windows WebView2 to load AI services such as Grok and Microsoft Copilot, fetching attacker-controlled URLs whose content the assistant returned and the malware parsed for instructions. Because the PoC required no account or API keys, this relay can blend into trusted traffic and complicate network-level blocking and attribution; platform safeguards exist but can be evaded through obfuscation.
read more →

Cryptojacking Campaign Uses Signed Driver to Boost Monero

🛡️ Trellix uncovered a multi-stage cryptojacking campaign that spreads via pirated software installers and deploys a customized XMRig miner alongside a stateful controller. The dropper installs a primary Explorer.exe controller and multiple watchdog processes for persistence, with a hardcoded expiry of December 23, 2025. Attackers load a signed vulnerable driver (WinRing0x64.sys/CVE-2020-14979) to gain kernel access and disable CPU prefetchers, boosting Monero RandomX performance by an estimated 15–50%. Researchers observed connections to the Kryptex pool and recommend enabling Microsoft's vulnerable driver blocklist, restricting USB access and blocking known mining pool traffic.
read more →

Keenadu Preinstalled Android Malware Compromises Firmware

⚠️ Kaspersky researchers have uncovered Keenadu, a multifaceted Android malware family that can be embedded in device firmware and run with system-level privileges from first boot. Detected on more than 13,000 devices across multiple countries, the backdoor impersonates legitimate system components (including face-unlock and home-screen apps) and can infect other apps, install APKs, and harvest sensitive data. It may remain dormant under certain locales and lacks easy removal through standard user tools. Kaspersky recommends checking firmware updates, running security scans, disabling suspect apps, and coordinating with vendors to address supply chain integrity.
read more →

Chinese APT Exploited Dell RecoverPoint Zero-Day Since 2024

🔒 Dell has released a patch for a critical zero-day, CVE-2026-22769, in RecoverPoint for Virtual Machines after Mandiant reported exploitation by a suspected Chinese APT cluster since mid-2024. The flaw is a hardcoded credential that enables unauthenticated access to the underlying OS and potential root-level persistence on versions prior to 6.0.3.1 HF1. Mandiant links the intrusions to UNC6201, which deployed malware such as Slaystyle, Brickstorm and a native AOT C# backdoor called Grimbolt, and observed novel TTPs including VM "ghost NICs" and iptables-based single-packet authorization.
read more →

Keenadu Firmware Backdoor Infects Android Tablets Worldwide

🔒 Kaspersky researchers have identified a firmware-embedded backdoor named Keenadu that can run in the context of every Android app and grant remote control over infected tablets. The implant was discovered in Alldocube iPlay 50 mini Pro firmware dating to August 18, 2023, and the compromised images carried valid digital signatures. Kaspersky observed delivery via signed OTA updates, preinstalled system apps, and trojanized apps distributed through third-party stores and official marketplaces.
read more →

Keenadu backdoor found in Android firmware and apps

🛡️ Keenadu is a sophisticated Android backdoor discovered embedded in device firmware and in apps distributed through Google Play and other channels. Kaspersky reports multiple distribution vectors — compromised OTA firmware, system apps, modified APKs and even Play Store apps — with the firmware-integrated variant being the most powerful. That variant can operate inside every installed app, silently install APKs with broad permissions, and exfiltrate media, messages, credentials and location data. Kaspersky has confirmed roughly 13,000 infected devices and warns that firmware-resident instances cannot be removed by standard Android tools; users should reflash clean firmware or replace affected devices.
read more →

SmartLoader Trojans Oura MCP Server to Deliver StealC

🛡️Researchers at Straiker's AI Research (STAR) Labs disclosed a SmartLoader campaign that distributes a trojanized Oura Model Context Protocol (MCP) server to deploy the StealC infostealer. Attackers built a deceptive network of fake GitHub accounts and forks, added sham contributors, and submitted the malicious server to the MCP Market to exploit developer trust. The delivered ZIP runs an obfuscated Lua script that drops SmartLoader, which then installs StealC to exfiltrate credentials, browser passwords, and cryptocurrency wallet data. Organizations should inventory MCP servers, verify provenance before installation, and monitor for suspicious egress and persistence.
read more →

ZeroDayRAT toolkit sells cross-platform mobile spyware

📱 ZeroDayRAT is a commercially marketed, cross-platform spyware toolkit distributed openly via Telegram that targets Android and iOS devices. iVerify traced initial activity to 2 February and found the offering includes an APK for Android, an iOS payload, a web-based management panel, documentation, and customer support channels. The malware harvests messages, call logs, contacts, location, photos, files, notifications, and enumerates accounts across popular services, enabling sustained surveillance and potential financial theft. Infection relies on social engineering—sideloading or iOS provisioning profiles—so iVerify recommends mobile EDR, stricter controls on unauthorized installs, and detection across BYOD and managed fleets.
read more →

Infostealer Targets OpenClaw, Exfiltrating AI Agent Data

🔐 Security researchers have documented an infostealer attack that exposed sensitive files from local AI assistants, specifically OpenClaw. Hudson Rock reported the malware harvested configuration and key material—including openclaw.json, device.json, and agent memory files—allowing token theft, private key access, and capture of users' operational context. The incident underscores risks from plaintext secrets and permissive defaults in agentic tools.
read more →