< ciso
brief />
Tag Banner

All news with #mobile security tag

229 articles

ToxicPanda Android malware adds VPN and ADB abuse

🛡️ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more →

Android head-unit malware expands automotive botnets

🔍 In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more →

Manic Android Malware Targets Banks and Messaging

🛡️ Manic is a recently observed Android threat combining banking malware and mobile spyware to target Ukrainian banks, government and identity services, messaging apps, and financial institutions across Europe. It is distributed via phishing sites and dropper apps impersonating utilities and abuses Android accessibility and notification permissions to capture credentials and perform device takeover. The family includes wrappers and implants with enhanced anti-analysis checks and can exfiltrate data via a novel multi-hop Wi‑Fi mesh relay using nearby compromised devices. ThreatFabric attributes active development to early 2026 with new deployments in July that introduced stronger lock-screen phishing and expanded capabilities.
read more →

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Unisoc modem exploit chain risks Android kernel

🔒 SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more →

QR code phishing risks and corporate defenses

🛡️ QR codes have become ubiquitous in daily life and are increasingly used in email-based attacks known as "quishing." These attacks encode malicious URLs in QR images to bypass traditional email filters and move victims from managed corporate devices to less-protected personal phones. Threat actors exploit brand impersonation and urgency to harvest credentials, bypass app stores, push fraudulent payments, or capture MFA tokens. Organizations should combine user training, email and mobile security, phishing-resistant MFA, MDM, and incident response planning to reduce risk.
read more →

Apple Alerts Users of Mercenary Spyware in 110 Countries

🔔 Apple has sent fresh threat notifications to an unspecified number of customers it suspects were targeted by mercenary spyware in 110 countries, adding to over 150 countries notified since late 2021. The company characterizes these as high-confidence alerts for individuals likely singled out due to their roles, such as journalists, activists, politicians, and diplomats. Apple declined to attribute the attacks to specific actors and cautioned that sharing diagnostic details could help attackers refine tactics. It provides notifications via iPhone alerts, email from "threat-notifications@email.apple[.]com," and a banner on the user's Apple Account page, and recommends security steps including updating software, enabling 2FA, and using Lockdown Mode.
read more →

Apple issues new threat notifications over spyware

🔔 Apple sent a fresh batch of threat notifications on August 13 alerting select iPhone users to suspected mercenary spyware attacks. These high-confidence alerts, issued since 2021, target a small set of users such as journalists and activists and do not name specific spyware or attribution. Apple warns users to verify genuine messages via account.apple.com and avoid links or requests for credentials, recommending Lockdown Mode and expert help if affected.
read more →

AmnesiaStealer targets macOS Chromium sessions

🛡️ Researchers disclosed a new Rust-based macOS infostealer, AmnesiaStealer, delivered via a fake GitHub “Download for macOS” page that tricks users into pasting a Base64 command into Terminal. The multi-stage dropper retrieves a password-protected ZIP and executes a Rust payload that harvests Keychain items, browser data, Apple Notes, Telegram, and files, while using the captured system password for privileged access. A second-stage remote_stream module enables operator-driven browser control over Chromium-family browsers via the Chrome DevTools Protocol to steal live sessions and evade detection.
read more →

WindRelay NFC Android Relay Malware Emerges

🔒 WindRelay is a new Android NFC relay malware deployed alongside the SpyNote RAT to enable contactless payment fraud. First observed in August 2025, it captures live card data via NFC and streams it in real time to fraudsters. Attackers use personalized social engineering and remote access to sideload the NFC reader covertly, turning the victim's phone into a payment proxy. The scheme pairs a victim-side reader with an attacker-side emulator and a shared C2 channel to relay EMV commands and enable card-present cashouts.
read more →

WhatsApp launches on-device scam alert beta

🔔 WhatsApp has started a limited beta for an optional Scam Alert that runs an on-device machine learning model to warn users of likely scam messages. The feature analyzes linguistic signals and conversational structure for messages from non-contacts, displaying a chat warning that suggests blocking, reporting, or continuing. No message content or the model leaves the device; users can mark chats as trusted or opt to share recent messages to improve accuracy. Scam Alert complements existing security updates aimed at preventing account takeover and spyware attacks.
read more →

Malicious SIMs can remotely commandeer cellular modules

🔒 Researchers from the University of Birmingham and Fuzzware demonstrate that a hostile SIM card can use the SIM's standard proactive commands (RUN AT) to instruct modems to execute AT commands, enabling code execution on affected devices. They tested 26 devices and found nine accepted the command, including several Quectel modules in EV chargers, industrial routers, and car telematics units. Vendors including Qualcomm and Quectel have responses in progress, but no public advisories have been broadly published.
read more →

Prosecution Over Phone Wipe Raises Border Search Questions

🔐 The prosecution of an American who provided a code that wiped his GrapheneOS-powered Pixel phone highlights tensions at the U.S. border. The feature in GrapheneOS deliberately erases device contents when a specific passcode is entered, and the defendant’s phone ran this OS. The case probes constitutional protections at the border and the government’s stance that border zones are not subject to the same rights until entry is authorized. GrapheneOS maintains the feature is legal and constitutionally protected.
read more →

Source Code Leak Exposes Flying Eagle Android RAT

🛡️ Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with Hunt.io and researcher NetAskari tracing matching control panels and certificates to 170 internet servers. The toolkit is linked to a fake Chinese Public Security app that can capture payments, keystrokes, record screens, use cameras, and display phishing prompts for finance and government services. Chinese authorities urged removal, password changes, and reporting while investigators note the server count does not prove active infections.
read more →

Managing risks of AI-powered smart glasses in enterprises

🕶️ As AI-powered smart glasses from Samsung and others enter workplaces, CISOs and IT leaders must weigh enterprise restrictions against enforcement and accessibility challenges. Device settings are controlled by individual wearers and AI guardrails can fail, making policy enforcement difficult. Experts recommend tiered policies, targeted bans in sensitive spaces, and robust user education rather than blanket prohibitions to balance security and accessibility.
read more →

Google phone verification and RCS privacy risks

📱 Google’s phone number verification notifies users when their SIM is confirmed and links that number to all Google accounts on the device. The feature supports RCS messaging and fraud protection but can surface hidden verification SMS or metadata collection. Verification runs by default, may use carrier APIs or hidden SMS, and can attach identifiers like ICCID/IMSI. Users can opt out per account but may lose RCS and risk re-enablement.
read more →

LG to ban residential proxies from smart TV apps

🛡️ LG Electronics USA will suspend smart TV apps that convert televisions into always-on residential proxy nodes, following research showing over 42% of webOS apps contain such proxy SDKs. The company is working with developers to remove the option and will suspend noncompliant apps, while tightening its app evaluation process. Spur’s research also found similar proxy components in Samsung’s Tizen apps, and proxy providers such as Bright Data were commonly identified. LG emphasized ongoing platform reviews to protect users.
read more →