< ciso
brief />
Tag Banner

All news with #mobile security tag

246 articles

Samsung Galaxy S26 Hacked Multiple Times at Pwn2Own

๐Ÿ”’ On day two of Pwn2Own Ireland 2026, researchers earned $232,500 after exploiting 45 distinct zero-day vulnerabilities. The Samsung Galaxy S26 was compromised three times by teams including KAIST Hacking Lab, PetoWorks, and Mobile Hacking Lab. Other notable wins included a rapid Sonos Era 300 exploit and a $40,000 award for breaching Dynamo in the AI Infrastructure category. ZDI enforces vendor 90-day patch windows after disclosure.
read more โ†’

Android 17 locks Accessibility API under Advanced Protection

๐Ÿ”’ Google announced that Android 17 will restrict access to the AccessibilityService API to verified apps labeled as Accessibility Tools when Advanced Protection is enabled. The change aims to close a frequent attack vector abused by banking trojans and spyware while preserving assistive capabilities. Android 17 also introduces features like Intrusion Logging, USB Protection, Disabled WebGPU, Failed Authentication Lock, and visibility into apps checking Advanced Protection status.
read more โ†’

Understanding the Risks of Vibeโ€‘Coded Mobile Apps

๐Ÿ”’ Vibe coding lets developers generate apps quickly using AI, but this speed can introduce security and privacy oversights. Common issues include hardcoded secrets, missing input validation, weak encryption, and public-by-default settings that expose user data. Users should vet apps by checking the developer's reputation, permissions requested, privacy policy, security model, and any AI access. If an app is breached, change passwords, enable MFA, revoke connected permissions, and consider uninstalling or factory-resetting compromised devices.
read more โ†’

Unpatched OnePlus flaws let installed apps gain root

๐Ÿ”’ A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app that requests no special permissions. Researcher Rasmus Moorats chained two vendor services to gain root: one that accepts arbitrary calls and injects text into system commands, and another that executes shell instructions when invoked as root. OnePlus confirmed the flaws in May, claimed exclusive control over disclosure, and had not released a patch when Moorats published on September 24.
read more โ†’

RatHat Android malware uses AI for adaptive control

๐Ÿ›ก๏ธ Zimperium zLabs discovered RatHat, an Android malware that leverages an AI-powered subsystem to remotely navigate compromised devices. Distributed via malvertising, SMS, and phishing sites hosting APKs, RatHat abuses Accessibility permissions to enable Developer Options and Wireless Debugging. It installs a Go-based agent for ADB-level commands, persistence, and self-restoration, and a second agent for persistent FRP reverse-proxy tunnels. The malware overlays HTML on banking and crypto apps, intercepts SMS and notifications, captures credentials and unlock patterns, and uses anti-analysis techniques to evade detection.
read more โ†’

Early Access creates blind spots for malicious apps

๐Ÿ” New research from Bitdefender Labs finds Google's Early Access program can shield deceptive apps from public scrutiny, since users cannot rate or review apps while they remain in Early Access. Analysts identified thousands of suspicious apps โ€” including fake casino and reward games, misleading utilities, and apps using known trademarks โ€” many promoted via social media and some using deepfake ads. Researchers warn certain utilities request unusual permissions or exhibit behaviors that could expose enterprise devices to serious risks.
read more โ†’

Mantax Otax Android malware combines ransomware, spyware

๐Ÿ”’ A new Android threat, Mantax Otax, combines ransomware and spyware to encrypt files, steal sensitive data, and harass victims. Distributed via malicious APKs outside Google Play by Indonesian operators, it requests Accessibility permissions to gain extensive control and retrieves its C2 domain from GitHub. The malware targets older Android versions for encryption, abuses Firebase and WebSockets for commands, and includes remote-control, data-exfiltration, and intimidation features. Up-to-date devices with Play Protect are generally protected, and users are advised to avoid sideloading APKs and granting Accessibility access to untrusted apps.
read more โ†’

Google Play Early Access abused to host scams

๐Ÿ” Threat actors are exploiting Google Play's Early Access program to distribute deceptive apps that promise money, rewards, casino wins, and premium content. Because Early Access apps do not accept public reviews or star ratings, malicious titles can gain traction without community warnings, and are often promoted via social media ads using AI-generated deepfakes. Reported examples include a Grand Theft Auto imitator with over a million downloads and numerous fake reward and utility apps that stall payouts and monetize victims via ads.
read more โ†’

MantaxOtax Android malware blends ransomware and spying

๐Ÿ›ก๏ธ Zimperium's zLabs detailed the MantaxOtax Android threat, linking it to Indonesian actors and noting distribution via sideloaded packages. The malware requests extensive privileges including Accessibility and device admin, enabling file encryption on older Android versions and broad surveillance on all supported devices. Operators resolve C2 domains via a GitHub-hosted pointer and use Firebase for extortion chats, with a misconfiguration exposing some dialogues. Variants add persistent locking, overlays, recording, and other disruptive behaviors to coerce victims.
read more โ†’

Gigabud Uses Work Profiles to Clone Banking Apps

๐Ÿ”’ Group-IB researchers revealed that the Gigabud Android banking trojan has been paired with a weaponized fork of the cloning app Shelter called Vwork, enabling attackers to clone banking apps into isolated Android work profiles. This separation hides malicious activity from signature-based detection in the personal profile and allows fraudsters to perform transactions that appear to originate from clean devices. The campaign was observed primarily in Indonesia but targets users across 11 countries and exploits accessibility and overlay permissions to capture credentials and one-time codes.
read more โ†’

US Military Disables Ad Tracking on Government Phones

๐Ÿ”’ Branches of the US military have disabled advertising IDs on government-issued phones and computers after concerns that commercially available location data was being used to target American forces. Senator Ron Wyden and Representative Pat Harrigan pushed the Pentagon for action and sought an inspector general investigation into how location data risks were handled. The move follows warnings about adversary exploitation of commercial location data and broader guidance urging personnel to limit personal device sharing and clean up social media.
read more โ†’

Packed Android RAT with ADB worm spreads via exposed services

๐Ÿ” Dark Atlas researchers detailed a packed Android remote access trojan (RAT) tracked as THost9 that conceals a loader inside an app and loads a second-stage payload, tc9.dex. The loader decodes and decompresses an embedded asset, starts a foreground service, and can enable an accessibility service when permissions allow. The second stage adds shell execution, file transfer, tunneling, reverse shell and downloadable modules, and includes a worm that scans for exposed Android Debug Bridge (ADB) services to propagate. Analysts linked infections to public ADB and Redroid exposures and recommend removing public ADB access and auditing accessibility services and persistent Redroid data.
read more โ†’

Pegasus zero-click iMessage exploit hits Serbian activists

๐Ÿ” The Citizen Lab and SHARE Foundation found that an iPhone linked to Serbia's student protest movement was infected via an iMessage zero-click exploit delivering NSO Group's Pegasus spyware. Analysis showed high-confidence indicators of infection between December 2025 and January 2026, and Apple addressed the exploited vulnerability in iOS 18.4.1. Multiple activists, politicians and students in Serbia have been targeted with advanced spyware amid the 2026 election period.
read more โ†’

AI-assisted iPhone theft and criminal 'SaaS' service

๐Ÿ” On Smashing Security episode 483, Graham Cluley and guest James Ball discuss how AI is being used to help thieves bypass protections and steal Apple iPhones. They outline the evolution of Apple's Activation Lock and how criminal groups like AnonymousKit operate as a criminal SaaS with customer support and Telegram testimonials. The hosts recount personal phone-theft experiences and highlight the ongoing challenges despite Apple's strengthened safeguards.
read more โ†’

Android 17 adds OSโ€‘wide ECH to shield connections

๐Ÿ”’ Google announced Android 17 will add systemโ€‘level support for Encrypted Client Hello (ECH) to obscure domain names and prevent network eavesdropping. The update enables ECH GREASE by default so connections to nonโ€‘ECH servers remain indistinguishable, and OkHttp has integrated ECH for thirdโ€‘party apps. Android 17 also enforces Local Network Protection, enables Certificate Transparency by default, and allows carriers to disable 2G to mitigate downgrade and SMS blaster attacks.
read more โ†’

Android 17 Adds ECH to Strengthen Connection Privacy

๐Ÿ”’ Android 17 introduces network protections including support for Encrypted Client Hello (ECH) to hide visited domain metadata and work alongside private DNS. The platform-level ECH support encrypts the TLS Client Hello hostname, reducing ISP and Wiโ€‘Fi operator visibility when using compatible apps and browsers. ECH will be enabled by default for apps targeting Android 17 that use supported networking libraries, with a GREASE fallback for nonโ€‘ECH servers to avoid detection.
read more โ†’

Fake recruiter phishing targets corporate mobile logins

๐Ÿ” Researchers at Zimperiumโ€™s zLabs uncovered recruitment-themed phishing campaigns that target corporate credentials on mobile devices by presenting full-screen counterfeit login pages and rejecting personal email domains to prioritize enterprise accounts. The activity, linked to RecruitTrap, impersonated major employers and persisted across cloud, hosting and domain-parking providers, exposing gaps in URL blocklists. Zimperium recommends securing mobile identity touchpoints and dynamically inspecting network traffic to detect credential harvesting.
read more โ†’

ToxicPanda Android malware adds VPN and ADB abuse

๐Ÿ›ก๏ธ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more โ†’

Android head-unit malware expands automotive botnets

๐Ÿ” In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFunโ€™s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more โ†’

Manic Android Malware Targets Banks and Messaging

๐Ÿ›ก๏ธ Manic is a recently observed Android threat combining banking malware and mobile spyware to target Ukrainian banks, government and identity services, messaging apps, and financial institutions across Europe. It is distributed via phishing sites and dropper apps impersonating utilities and abuses Android accessibility and notification permissions to capture credentials and perform device takeover. The family includes wrappers and implants with enhanced anti-analysis checks and can exfiltrate data via a novel multi-hop Wiโ€‘Fi mesh relay using nearby compromised devices. ThreatFabric attributes active development to early 2026 with new deployments in July that introduced stronger lock-screen phishing and expanded capabilities.
read more โ†’