Threats Tagged 'android'
View all threats tagged with 'android'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'android'
Click on any threat for detailed analysis and mitigation recommendations
Inside the Underground Business of the Android BTMOB RAT malware 0 BTMOB is an Android remote access trojan (RAT) malware-as-a-service operation that has evolved from a centrally managed service into a fragmented underground ecosystem. This ecosystem includes resellers, source-code vendors, custom versions, and competing sales channels, complicating attribution and control. The malware enables attackers to steal information and remotely control infected Android devices. The original operator has sold source code and infrastructure access, leading to multiple independent versions and impersonators. The official operation continues to release new versions and sell access, but cheaper and potentially unauthentic alternatives circulate widely. Buyers face risks related to the legitimacy and quality of these offerings. Join the discussion | Bleeping Computer | 08/03/2026, 14:45:55 UTC Added: 08/04/2026, 17:47:13 UTC |
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave 0 A set of three vulnerabilities were discovered in the BigWave driver on the Pixel 9 device, which is accessible from the mediacodec sandboxed context. One of these bugs enables a use-after-free condition that allows escaping the mediacodec sandbox and achieving arbitrary kernel read/write on the Pixel 9. The vulnerabilities were fixed on January 5, 2026. The BigWave driver accelerates AV1 decoding and is exposed to userland processes in the mediacodec SELinux context, which is intended to be constrained. The use-after-free arises from a race condition between ioctl processing and a worker thread handling hardware jobs, leading to a kernel object being freed while still referenced. Join the discussion | Google Project Zero | 01/14/2026, 18:00:00 UTC Added: 08/04/2026, 12:57:56 UTC |
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft 0 In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by ReliaQuest on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID. Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems. Microsoft has observed Storm-2945 leveraging AI to support a significant portion of these operations. Today, we are sharing our findings on these ongoing intrusions to raise awareness of this threat and enable customers to protect their devices, especially while traveling. We provide our assessment of Storm-2945’s relationship to Midnight Blizzard and analysis of the CaptiveCrunch campaign, detailing the malware and tradecraft used in these operations. We also provide mitigation, detection, and hunting guidance to help organizations identify and defend against Storm-2945 and related activity. Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation. The CaptiveCrunch campaign Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365. Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem. Figure 1. Overview of the CaptiveCrunch attack flow As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users’ browsers. Multiple variants have been delivered, including fully-featured Windows remote access trojans (RAT) in compiled Golang, with functionality to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. The threat actor infrastructure leverages a variety of ClickFix techniques to elicit the user into downloading and executing the malware: Figure 2. ClickFix prompt with manual user instructions Figure 3. ClickFix prompt with additional user instructions after verification failure In addition to variants of malware targeting Windows systems, Microsoft Threat Intelligence is also aware of indications that the threat actor might be targeting Android devices with similar techniques as the ClickFi… Join the discussion | Microsoft Security Blog | 07/31/2026, 21:01:37 UTC Added: 08/01/2026, 07:58:48 UTC |
Read This Before You Buy That TV Streaming Stick 0 Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro Falé is a threat researcher with the security firm Bitsight . Falé told KrebsOnSecurity he was able to peer inside a vast and complex ad fraud network by registering an expired domain name that was used to coordinate fake ad clicks across a particularly popular brand of these streaming devices known as H96 . An H96 TV streaming device currently advertised for sale on Amazon. Falé said the domain he scooped up was previously used for telemetry, periodically collecting full hardware information and the entire list of installed apps from tens of thousands of H96 streaming sticks plugged into television sets around the globe. But upon inspecting the traffic being funneled to the domain, he discovered nearly all of the TV boxes transmitting data claimed to be mobile phone models from a variety of manufacturers, including Samsung, Vivo, Huawei, and Xiaomi. “We noticed something was wildly wrong,” Falé said. “Multiple devices reporting to this factory Android TV Box backdoor were ‘phones.'” Image: Bitsight. The researcher found all of the devices reported having the same two apps installed, and that those apps were made by a company called Zhejiang Fengwo IoT Technology Ltd , an entity founded in 2019 in mainland China which operates an ad-publishing portfolio under the name Fengwo Group . Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps. “Bitsight TRACE identified several Hong Kong, Singapore, and single person ‘legal’ shell identities used to collect the monetization and traced the operation back to a mainland China company known as Zhejiang Fengwo IoT Technology Co., Ltd, which operates under the Fengwo Group,” Falé wrote in a report released today about their findings. Falé said an analysis of the apps shows they help to coordinate an ad fraud network that uses these H96 devices as a captive traffic source to click on ads at AI-generated websites operated by the Fengwo Group. Bitsight discovered the websites contain machine-generated news articles and graphics across a range of categories, including finance, health, education, gaming, music and food blogs. But they also found none of those sites displayed ads unless the device visiting the page matched the spoofed mobile profile of these H96 devices. AI DIGITAL HUMANS The domain for the Fengwo Group — fwgcloud[.]com — claims the company is “redefining the boundaries of human-AI interaction,” and that it has created more than 120,000 “AI digital humans” available to rent for everything from emotional companionship to 24/7 customer service and creative design. The homepage for fwgcloud dot com. Falé said the Fengwo Group’s domain shared its SSL certificate data with other domains associated with the apps found on H96 devices, specifically the phone spoofing mechanism. He noted the domain also has an internal wiki platform that directly ties the Fengwo Group to a proprietary implementation of a Google-built visual programming language called Blockly , which was originally designed to help kids learn how to write software. According to Bitsight, the Fengwo Group’s employees use Blockly to build the sham websites, allowing low-skilled operators to drag blocks of code together in their Blockly editor — without any need to understand what the underlying code blocks do or how they work. The Blockly homepage. “An operator can drag blocks together in their Blockly editor, to define each fraud routine, given a task type,” reads Bitsi… Join the discussion | Krebs on Security | 07/30/2026, 16:49:00 UTC Added: 07/31/2026, 01:31:43 UTC |
Microsoft Patches a Record 570 Security Flaws 0 Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild. Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164 , a Microsoft Sharepoint vulnerability. CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation. In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities. “The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,” Davuluri wrote . Jack Bicer , director of vulnerability research at Action1 , called attention to CVE-2026-48561 , a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site. As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its “exploitability index,” which is Redmond’s best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability. But Satnam Narang , senior staff research engineer at Tenable , argues that Microsoft’s exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was added to CISA’s Known Exploited Vulnerabilities list on July 1. “Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely,'” Narang said. “What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.” Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco , Mozilla and Oracle also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more t… Join the discussion | Krebs on Security | 07/14/2026, 19:22:42 UTC Added: 07/14/2026, 19:30:15 UTC |
RedHook Android malware now uses Wireless ADB for shell access 0 The RedHook Android malware has evolved to abuse the Android Wireless Debugging (Wireless ADB) feature to gain shell-level privileges without requiring a computer connection or device rooting. It tricks users into granting Accessibility permissions to enable Developer Options and Wireless Debugging, then uses the pairing code to connect to the local ADB service. This grants it UID 2000 shell privileges, allowing it to execute privileged commands, install or uninstall apps silently, capture screen content, simulate user input, and more. The malware employs multiple persistence mechanisms to maintain its presence and is distributed via social engineering campaigns impersonating government or financial institutions. Android users are advised to install apps only from Google Play and scrutinize permissions carefully. Join the discussion | Bleeping Computer | 07/12/2026, 14:27:32 UTC Added: 07/12/2026, 15:02:37 UTC |
Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign 0 A malicious campaign was detected impersonating an Italian banking brand through a fraudulent domain offering fake financial rewards for installing a mobile application. Users are redirected to a Telegram bot that distributes a malicious Android APK outside official app stores. The APK functions as a dropper containing an embedded second-stage payload identified as Albiriox, an Android banking Remote Access Trojan. This payload exploits Accessibility services, implements overlay attacks, intercepts SMS messages, captures credentials, and enables remote device control through a custom TCP-based command-and-control protocol. The infrastructure uses domain impersonation and social engineering with financial incentives to distribute the malware. Communication occurs via raw TCP sockets to endpoints on ports 5555 and 5552, with JSON messages framed using big-endian length prefixes. Attribution to Albiriox is supported by protocol similarities, behavioral patterns, and comparison with known Albiriox samples. Join the discussion | AlienVault OTX General | 07/09/2026, 22:16:05 UTC Added: 07/10/2026, 07:47:32 UTC |
Showing 1 to 7 of 7 results