Uncovering StreamRat: From Meta Ads to Full Device Takeover
https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
ThreatFabric
Uncovering StreamRat: From Meta Ads to Full Device Takeover
ThreatFabric researchers have uncovered StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok advertisements.
⚡37
Your photos can be accessed without unlocking your Android when you receive a WhatsApp video call [not fixed]
https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/
https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/
Mobile Hacker
WhatsApp Lets You View Photos Without Unlocking Smartphone - Mobile Hacker
Most people assume that once their phone is locked, their photos are protected from anyone who picks up the device. However, a behavior discovered Jose Rodriguez shows that photos may be accessible during an incoming WhatsApp video call, even while the phone…
😁20🔥13👍11❤10🤯8⚡5
How to Copy and Backup RFID Access Cards and NFC Key Fobs with Chameleon Ultra
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
Mobile Hacker
Chameleon Ultra: Guide to RFID Reading, Emulation and Testing - Mobile Hacker
Contactless cards and key fobs are now part of everyday life. They unlock apartment buildings, identify employees, open hotel rooms, record attendance and interact with electronic locks. Although many of these credentials look similar from the outside, the…
👍28🔥15
1-click could expose every contact saved on your Android, even if you never gave permission to access them (CVE-2026-28576)
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
👍22🔥12❤8
TeleGapper is a black-box dynamic analysis tool for Telegram Mini Apps on Android devices
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
GitHub
GitHub - Mobile-IoT-Security-Lab/TeleGapper: Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations
Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations - Mobile-IoT-Security-Lab/TeleGapper
👍20🥴19🤮3
Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
🎃29❤3
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
https://calif.io/research/weworm
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
🔥29❤12
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
❤29👍19
Vwork: Weaponized Open-source Software as an Addon for Gigabud
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
Group-IB
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
👍25
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
Zimperium
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
true
⚡15❤9
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Zimperium
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
true
❤14😁10⚡5
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
Mobile Hacker
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC - Mobile Hacker
Do you have an older rooted Android phone sitting unused in a drawer? Instead of leaving it there, you can turn it into a practical NFC reader and USB keyboard for your computer. With a custom Android app (NFC to HID), your phone can read the unique indentation…
👍13❤6