Threats Tagged 'device takeover'
View all threats tagged with 'device takeover'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'device takeover'
Click on any threat for detailed analysis and mitigation recommendations
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:22:26 UTC |
A new variant of the TrickMo Android banking trojan was identified between January and February 2026, representing a substantial platform redesign rather than new capabilities. The malware has migrated its command-and-control infrastructure entirely onto The Open Network (TON) using .adnl endpoints, moving away from conventional internet infrastructure. Active campaigns have targeted banking and wallet users in France, Italy, and Austria. Once accessibility permissions are granted, operators gain real-time device control including credential phishing, keylogging, screen recording, SMS interception, and bidirectional remote control. New features include network reconnaissance capabilities and SSH tunnelling that transform infected devices into programmable network pivots and SOCKS5 proxy exit nodes, enabling operators to bypass IP-based fraud detection systems while accessing victim networks. Join the discussion | AlienVault OTX General | 05/11/2026, 09:07:43 UTC Added: 05/11/2026, 09:51:23 UTC |
A new Android banking Trojan named Massiv has been discovered, posing a significant threat to mobile banking users. This malware allows remote control of infected devices and enables Device Takeover attacks, leading to fraudulent transactions from victims' accounts. Massiv is distributed through side-loading, often masquerading as IPTV applications. It features overlay functionality, keylogging, and SMS/Push message interception to steal sensitive data. The malware has targeted government applications and digital identity wallets, particularly in Portugal. Massiv supports screen streaming and UI-tree modes for remote control, bypassing screen capture protections. The trend of malware masquerading as IPTV apps is increasing, exploiting users' willingness to install from unofficial sources. Join the discussion | AlienVault OTX General | 02/19/2026, 11:04:35 UTC Added: 02/19/2026, 12:50:31 UTC |
Herodotus is a newly discovered Android malware designed to perform device takeover by mimicking human behavior to evade biometric and automated detection. It is distributed via side-loading and targets financial organizations and cryptocurrency wallets, with active campaigns observed in Italy and Brazil and potential for global spread. The malware is offered as Malware-as-a-Service and is linked to the Brokewell malware family. It steals credentials and remotely controls infected devices, using randomized delays between inputs to simulate human interaction. This behavior mimicry complicates detection by security solutions relying on behavioral analysis. The malware’s focus on financial targets and crypto wallets poses significant risks to confidentiality and financial integrity. European organizations, especially in Italy and Poland, are currently targeted and should prepare for potential expansion. Mitigation requires advanced layered security, including strict app installation policies, behavioral anomaly detection tuned for such mimicry, and user education on side-loading risks. Join the discussion | AlienVault OTX General | 10/28/2025, 18:24:45 UTC Added: 10/28/2025, 19:25:46 UTC |
Showing 1 to 4 of 4 results