Threats Tagged 'android'
View all threats tagged with 'android'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'android'
Click on any threat for detailed analysis and mitigation recommendations
RatHat is an Android trojan that uses generative AI to automate real-time device navigation and control, enhancing its adaptability and evasion capabilities. It steals credentials, mimics banking apps, intercepts SMS, and gains administrator-level permissions. The malware persists by reinstalling itself if removed and uses advanced keylogging techniques, including hardware-level monitoring of user input. It communicates with a command-and-control server via a secure reverse tunnel and abuses Android debugging tools for system-level access. RatHat is distributed through smishing and malvertising and appears linked to a Chinese threat actor. Join the discussion | SecurityWeek | 09/21/2026, 12:51:41 UTC Added: 09/21/2026, 13:01:39 UTC |
RatHat is a newly discovered Android malware that leverages AI to automate remote control of infected devices. It abuses Android Accessibility permissions to perform privileged actions, including enabling Developer Options and Wireless Debugging to gain shell-level access without external devices. RatHat installs a persistent Go-based agent that manages execution, persistence, and restoration of the malware and its components. It captures sensitive information such as banking credentials, SMS messages, one-time passwords, and lock-screen PINs via overlays and keylogging. The AI subsystem enables adaptive interface navigation by analyzing the live Accessibility tree and issuing dynamic commands, making detection and removal more difficult. The malware also employs anti-analysis and anti-removal techniques, including fake uninstall screens and obfuscation methods. Distribution occurs through malvertising, SMS, and phishing sites promoting APKs outside Google Play. Join the discussion | Bleeping Computer | 09/17/2026, 21:50:26 UTC Added: 09/17/2026, 22:16:45 UTC |
Google released the September 2026 security patches for Pixel devices addressing 110 vulnerabilities, including one zero-day flaw that was actively exploited in targeted attacks. The update mitigates this actively exploited vulnerability to protect affected devices. Join the discussion | Bleeping Computer | 09/16/2026, 07:00:19 UTC Added: 09/16/2026, 07:01:41 UTC |
The Android application "ManabiPocket for Parents" by NTT DOCOMO BUSINESS, Inc. has an improper access control vulnerability. This issue could allow unauthorized access to certain application functions or data due to insufficient access restrictions. No specific affected versions or technical details are provided, and no known exploits are reported. Patch or remediation status is not confirmed. Join the discussion | JVN Japan | 09/15/2026, 05:00:00 UTC Added: 09/15/2026, 05:07:38 UTC |
The Android application "YAMAP -Social Trekking GPS App" by YAMAP INC. has an improper access control vulnerability in its WebView component. This flaw could potentially allow unauthorized access to certain app functionalities or data due to insufficient access restrictions in the WebView implementation. Join the discussion | JVN Japan | 09/14/2026, 03:00:00 UTC Added: 09/14/2026, 03:06:26 UTC |
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...] Join the discussion | Bleeping Computer | 09/11/2026, 20:19:09 UTC Added: 09/11/2026, 20:31:58 UTC |
Mantax Otax is a newly identified Android malware strain that combines ransomware and spyware functionalities. It encrypts files on infected devices, steals sensitive user data, and additionally spams and harasses victims. This multifaceted malware poses a significant threat to Android users by compromising both data confidentiality and user experience. Join the discussion | Bleeping Computer | 09/10/2026, 21:40:43 UTC Added: 09/10/2026, 21:47:11 UTC |
Deceptive Android apps are exploiting Google Play's Early Access program to evade public reviews and ratings. Dishonest developers advertise these apps externally, promising rewards that never materialize, while the apps primarily serve aggressive advertisements. These apps often impersonate legitimate games or use trademark abuse and AI-generated misleading content. Although not delivering malware or clearly illegal content, this misuse harms users by wasting their time and exposing them to excessive ads. Join the discussion | SecurityWeek | 09/10/2026, 13:39:52 UTC Added: 09/10/2026, 13:52:14 UTC |
A sophisticated mobile threat linked to Indonesian actors combines ransomware and spyware capabilities in a single attack vector. The malware is distributed via third-party file-sharing platforms through social engineering, targeting Android devices. It requests extensive permissions including device administrator, SMS, contacts, and accessibility access. The threat encrypts files using AES on Android 9 and earlier, appending .enc extensions, while stealing sensitive data including screen recordings, browser history, PINs, contacts, call logs, SMS messages, WhatsApp and Telegram chats. It establishes C2 communication via HTTPS and WebSockets using dynamic domain resolution through GitHub. Version 2 introduces UI hijacking, screen blocking, touch input interception, harassment features, and remote text-to-speech capabilities. The malware exfiltrates data through Firebase and Catbox services, enabling double-extortion through an interactive chat portal for ransom demands. Join the discussion | AlienVault OTX General | 09/09/2026, 20:59:12 UTC Added: 09/10/2026, 09:22:42 UTC |
The September 2026 Android security updates address 180 vulnerabilities across the Framework, System, and Kernel components. The most critical issues include remote code execution flaws in the System component that require no user interaction or additional privileges. The updates are delivered in two parts, covering a wide range of Android runtime, Framework, System, and kernel components, as well as various chipset vendors. No specific patches were released this month for Wear OS, Android XR, or Android Automotive OS, but their updates include these fixes. The updates are critical for maintaining device security and preventing potential remote exploitation. Join the discussion | SecurityWeek | 09/09/2026, 16:30:40 UTC Added: 09/09/2026, 16:37:14 UTC |
Showing 1 to 10 of 139 results