Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
π34β€11
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
https://calif.io/research/weworm
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
π₯34β€18
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
β€33π24
Vwork: Weaponized Open-source Software as an Addon for Gigabud
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
Group-IB
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
π34β€5
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
Zimperium
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
true
β‘18β€15π1
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Zimperium
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
true
β€16π12β‘10
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
Mobile Hacker
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC - Mobile Hacker
Do you have an older rooted Android phone sitting unused in a drawer? Instead of leaving it there, you can turn it into a practical NFC reader and USB keyboard for your computer. With a custom Android app (NFC to HID), your phone can read the unique indentationβ¦
π20β€9π3
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
https://blog.nns.ee/2026/09/24/oneplus-root/
https://blog.nns.ee/2026/09/24/oneplus-root/
nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
β€14π₯7π€£2
RemControl: AI Built the Overlays. Victims Lose their PINs
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
Group-IB
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
β‘6β€2
A native APK and DEX decompiler written in Rust
https://github.com/Ch0pin/rdx
https://github.com/Ch0pin/rdx
GitHub
GitHub - Ch0pin/rdx: A native APK and DEX decompiler written in Rust
A native APK and DEX decompiler written in Rust. Contribute to Ch0pin/rdx development by creating an account on GitHub.
π±11β€7π7
apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis
https://github.com/newliver666/apk-reverse
https://github.com/newliver666/apk-reverse
GitHub
GitHub - newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis
Suitable for Android APK reverse engineering analysis - newliver666/apk-reverse
β€6π©5π4π1
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
Cleafy
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat | Cleafy
Cleafy's TIR team analyzed the operator infrastructure behind RATHat, an Android banking trojan that abuses Accessibility Services to enable wireless debugging on the victim's phone, obtain a shell, and deploy a hidden native service outside the app. Theβ¦
π3
How we found 24 Android vulnerabilities using our open source AI security agent
https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/
https://github.blog/security/how-we-found-24-android-vulnerabilities-using-our-open-source-ai-security-agent/
The GitHub Blog
How we found 24 Android vulnerabilities using our open source AI security agent
A look at the targeted AI taskflows behind these findings, the bugs they uncovered, and how to run the same open-source agent on your own app.