Threats Tagged 'android'
View all threats tagged with 'android'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'android'
Click on any threat for detailed analysis and mitigation recommendations
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum 0 Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum appeared first on SecurityWeek . Join the discussion | SecurityWeek | 06/19/2026, 15:23:36 UTC Added: 06/19/2026, 15:35:04 UTC |
Popa: From Sourcing to Distribution 0 An Android proxyware SDK named Popa enrolls consumer devices including phones, tablets, and streaming boxes into a commercial residential proxy network. Operating since at least 2020, Popa and its variants (Loopop, Neupop, and Moneytiser) are distributed inside consumer streaming, IPTV, and utility applications. The SDK begins relaying third-party traffic at host-app launch without displaying informed-consent prompts in analyzed samples. Multiple variants communicate directly with NetNut SDK endpoints, sharing operational infrastructure and telemetry. Controlled testing showed traffic from Popa-enrolled devices egressing through NetNut's commercial gateway. The SDK uses encrypted Google Drive files to resolve relay servers in later versions. Analysis of over 20 publishers revealed significant links to piracy-related applications, with none observed requesting user consent despite later builds including this capability. Join the discussion | AlienVault OTX General | 06/18/2026, 19:31:57 UTC Added: 06/19/2026, 09:35:47 UTC |
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm 0 For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. Join the discussion | Krebs on Security | 06/18/2026, 17:37:58 UTC Added: 06/18/2026, 17:50:17 UTC |
Rokarolla Banking Trojan Targets 200 Applications 0 The Android malware allows its operators to take control of infected devices and harvest sensitive information. The post Rokarolla Banking Trojan Targets 200 Applications appeared first on SecurityWeek . Join the discussion | SecurityWeek | 06/18/2026, 10:42:21 UTC Added: 06/18/2026, 10:51:22 UTC |
New Rokarolla Android malware targets 217 banking, crypto apps 0 A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...] Join the discussion | Bleeping Computer | 06/16/2026, 20:04:11 UTC Added: 06/16/2026, 20:15:14 UTC |
NFCShare Android malware spreads via fake banking app updates on GitHub 0 New variants of the NFCShare Android malware are being distributed as fake updates for legitimate banking apps hosted on GitHub. [...] Join the discussion | Bleeping Computer | 06/08/2026, 22:11:58 UTC Added: 06/08/2026, 22:18:36 UTC |
CISA warns of active attacks exploiting Android, Linux bugs 0 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...] Join the discussion | Bleeping Computer | 06/03/2026, 15:36:16 UTC Added: 06/03/2026, 15:48:37 UTC |
Google adds Android protection against AI deepfake scam calls 0 Google is introducing a new Android security feature that will detect and flag phone calls in which scammers use artificial intelligence to impersonate a user's personal contacts. [...] Join the discussion | Bleeping Computer | 06/03/2026, 09:02:11 UTC Added: 06/03/2026, 09:03:33 UTC |
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk 0 A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk appeared first on SecurityWeek . Join the discussion | SecurityWeek | 06/02/2026, 15:00:00 UTC Added: 06/02/2026, 15:03:33 UTC |
Google fixes one actively exploited Android zero-day, 124 flaws 0 Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks. [...] Join the discussion | Bleeping Computer | 06/02/2026, 11:10:15 UTC Added: 06/02/2026, 11:18:36 UTC |
Showing 1 to 10 of 13 results