Threats Tagged 'overlay attack'
View all threats tagged with 'overlay attack'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'overlay attack'
Click on any threat for detailed analysis and mitigation recommendations
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t... Join the discussion | AlienVault OTX General | 08/18/2026, 15:06:19 UTC Added: 08/18/2026, 19:49:41 UTC |
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation. Join the discussion | AlienVault OTX General | 08/12/2026, 13:20:44 UTC Added: 08/12/2026, 15:41:30 UTC |
A new Android Trojan masquerades as legitimate news reader or digital ID apps, stealthily stealing sensitive data by exploiting Android Accessibility Services and overlay features. It primarily targets banking and cryptocurrency applications by overlaying fake login screens to capture credentials. The malware operates silently in the background, connects to a remote command center for updates and cleanup, and has been observed mainly in Southeast Asia. Although no CVE or known exploits in the wild are reported, the malware's capabilities pose significant risks to user confidentiality and financial security. This threat highlights the importance of enhanced mobile security and user vigilance against fake apps and overlay attacks. Join the discussion | AlienVault OTX General | 11/05/2025, 12:36:23 UTC Added: 11/05/2025, 21:32:54 UTC |
Showing 1 to 3 of 3 results