Glitch SPY: New Android RAT Distributed Through a Fake Polish Rental App
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/
Cyble
Glitch SPY RAT Distributed Via Fake Polish Rental App
CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control.
RedWing: A Mobile Malware-as-a-Service Operation
https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation
https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation
Zimperium
RedWing: A Mobile Malware-as-a-Service Operation
true
π28β‘21π16β€14
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
https://zimperium.com/blog/goldpickaxe-returns-when-your-biometric-information-is-as-important-as-your-money
https://zimperium.com/blog/goldpickaxe-returns-when-your-biometric-information-is-as-important-as-your-money
Zimperium
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
true
π21π18β€13π5
How to Bypass mTLS on Android with Frida
https://kiratliygt.medium.com/how-to-bypass-mtls-on-android-with-frida-45c5e71373e8
https://kiratliygt.medium.com/how-to-bypass-mtls-on-android-with-frida-45c5e71373e8
Medium
How to Bypass mTLS on Android with Frida
Keywords: mTLS bypass Android, Frida mTLS, Android mutual TLS bypass, Burp Suite mTLS Android, Android mTLS pentest, PKCS12 Androidβ¦
π39β€23
RedHook Android malware abuses ADB Wireless Debugging and Shizuku to get shell-level privileges
https://www.group-ib.com/blog/redhook-android-rat-upgraded/
https://www.group-ib.com/blog/redhook-android-rat-upgraded/
Group-IB
RedHook Returns with a Dangerous Upgrade
Group-IB analysts examine this resurfaced Android Remote Access Trojan, demonstrating new, sophisticated and malicious functionalities including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack.
π19π15π€‘13β€8π₯8π8π1
Forwarded from The Bug Bounty Hunter
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
devploit / blog
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
What happens if an app without READ_CONTACTS asks Google Messages for Android to load a Contacts photo for it?
β€43π11
List of 140 vulnerabilities in Samsung preinstalled Android apps reported in 2022
https://github.com/oversecured/Samsung_Vulnerabilities
https://github.com/oversecured/Samsung_Vulnerabilities
GitHub
GitHub - oversecured/Samsung_Vulnerabilities: 176 vulnerabilities in Samsung preinstalled Android apps
176 vulnerabilities in Samsung preinstalled Android apps - oversecured/Samsung_Vulnerabilities
β€31π₯20β‘15
Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
Dreamgroup
How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post | | Dream Security Blog
π―12β€9π9π4
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
π12β€8π5
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
www.d3lab.net
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT β D3Lab
From a fake N26 support call to the Copybara Android RAT: inside a human-operated phishing campaign designed for on-device financial fraud.
β€13π4π₯±4π₯°2
Root My Pixel: is an Android application designed to automate root access on Google Pixel 10 devices leveraging the NebuSec IonStack exploit (CVE-2026-43499) and integrating ReSukiSU / KernelSU
https://github.com/alex193a/Root-My-Pixel
https://github.com/alex193a/Root-My-Pixel
GitHub
alex193a/Root-My-Pixel
Jailbreak supported Google Pixel phones with CVE-2026-43499 - alex193a/Root-My-Pixel
π₯16π13π±6β€4π3π1
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/
https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/
K7 Labs
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
Unlike traditional Android Remote Access Trojan (RAT), Android Octagon employs a multi-stage design that dynamically loads encrypted DEX and JAR [β¦]
β‘13β€11π6
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
Bitsight
Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud
Bitsight's TRACE team exposes the "Fuyao Enterprise," a hidden Android TV botnet using 120,000+ AI digital humans to power large-scale ad fraud. Learn more.
β€7
Zero-Click File Drop on Xiaomi ShareMe (MiDrop)
https://blog.byterialab.com/zero-click-file-drop-on-xiaomi-shareme-midrop/
https://blog.byterialab.com/zero-click-file-drop-on-xiaomi-shareme-midrop/
Byteria - Mobile Application Security Blog
Zero-Click File Drop on Xiaomi ShareMe (MiDrop) - Byteria - Mobile Application Security Blog
An attacker within Bluetooth LE range (about 50 m) can write arbitrary files to a victimβs phone the moment they open Receive mode. No QR scan
π₯11β€7β‘4