Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
Dreamgroup
How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post | | Dream Security Blog
π―15β€11π10π5
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
π19β€11π7
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
D3Lab
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT
From a fake N26 support call to the Copybara Android RAT: inside a human-operated phishing campaign designed for on-device financial fraud.
β€16π₯±7π6π₯°2
Root My Pixel: is an Android application designed to automate root access on Google Pixel 10 devices leveraging the NebuSec IonStack exploit (CVE-2026-43499) and integrating ReSukiSU / KernelSU
https://github.com/alex193a/Root-My-Pixel
https://github.com/alex193a/Root-My-Pixel
GitHub
GitHub - alex193a/Root-My-Pixel: Jailbreak supported Google Pixel phones with CVE-2026-43499
Jailbreak supported Google Pixel phones with CVE-2026-43499 - alex193a/Root-My-Pixel
π₯21π14π±8β€5π5π2
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/
https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/
K7 Labs
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
Unlike traditional Android Remote Access Trojan (RAT), Android Octagon employs a multi-stage design that dynamically loads encrypted DEX and JAR [β¦]
β€20β‘15π8
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
Bitsight
Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud
Bitsight's TRACE team exposes the "Fuyao Enterprise," a hidden Android TV botnet using 120,000+ AI digital humans to power large-scale ad fraud. Learn more.
β€19
Zero-Click File Drop on Xiaomi ShareMe (MiDrop)
https://blog.byterialab.com/zero-click-file-drop-on-xiaomi-shareme-midrop/
https://blog.byterialab.com/zero-click-file-drop-on-xiaomi-shareme-midrop/
Byteria - Mobile Application Security Blog
Zero-Click File Drop on Xiaomi ShareMe (MiDrop) - Byteria - Mobile Application Security Blog
An attacker within Bluetooth LE range (about 50 m) can write arbitrary files to a victimβs phone the moment they open Receive mode. No QR scan
π₯20β€11β‘9π1
Introducing MobHunt: agentic mobile bug bounty hunting
Blog: https://ivrodriguez.com/introducing-mobhunt/
Tool: https://github.com/ivRodriguezCA/MobHunt
Blog: https://ivrodriguez.com/introducing-mobhunt/
Tool: https://github.com/ivRodriguezCA/MobHunt
Ivrodriguez
Introducing MobHunt: agentic mobile bug bounty hunting
tl;dr I built an agentic mobile security research system that runs the whole mobile bug bounty pipeline, from scoping a program to writing the report. Here is what happened when I pointed it at real programs.
β€5π3π3π2
Dropping Elephant (Patchwork): Espionage APT Tactics and Tools
https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Picussecurity
Dropping Elephant (Patchwork): Espionage APT Tactics and Tools
Dropping Elephant, also called Patchwork, is an espionage APT active since 2015. Review its MITRE ATT&CK techniques and validate your controls.
β€5π3β‘1
Developers: Beware of Ad Libraries that Betray Your Usersβ Location Privacy
https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
Electronic Frontier Foundation
Developers: Beware of Ad Libraries that Betray Your Usersβ Location Privacy
An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing usersβ location by default when embedded in apps granted location
π11β€3
Striking gold: Inside the GoldDigger Android malware
https://www.ibm.com/think/security/golddigger-android-malware-analysis
https://www.ibm.com/think/security/golddigger-android-malware-analysis
Ibm
Striking gold: Inside the GoldDigger Android malware | IBM
IBM Trusteer's in-depth analysis of GoldDigger malware reveals how this sophisticated Android mobile banking Trojan uses virtual environments and evasion techniques. Learn to recognize the threat and protect yourself from bad actors.
π11
Kimwolf v7: An Evolution of the Kimwolf Android Botnet
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Unit 42
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
β€6π4
Bypassing Android Hardware Attestation from the Analyst's Chair
https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
Quarkslab
Bypassing Android Hardware Attestation from the Analyst's Chair - Quarkslab's blog
Hardware key attestation lets an Android app prove to its backend that a key lives in secure hardware on a locked, verified device. It is also the wall that stops a security analyst working on a rooted phone. This article opens the mechanism from the analyst'sβ¦
π11
LLM Obfuscation Detection Framework for Android Apps
https://github.com/Mobile-IoT-Security-Lab/LLMObfuscDetection
https://github.com/Mobile-IoT-Security-Lab/LLMObfuscDetection
GitHub
GitHub - Mobile-IoT-Security-Lab/LLMObfuscDetection: LLM Obfuscation Detection Framework for Android Apps
LLM Obfuscation Detection Framework for Android Apps - Mobile-IoT-Security-Lab/LLMObfuscDetection
β€15π₯3β‘2
LSPosed module for disabling SSL certificate pinning on Android
https://github.com/0xdad0/ssl-kill-switch-lsposed
https://github.com/0xdad0/ssl-kill-switch-lsposed
GitHub
GitHub - 0xdad0/ssl-kill-switch-lsposed: LSPosed module for disabling SSL certificate pinning on Android. Covers Java-layer pinningβ¦
LSPosed module for disabling SSL certificate pinning on Android. Covers Java-layer pinning (OkHttp, TrustManager, Conscrypt, WebView, Cordova, Tencent X5) and native-layer pinning (BoringSSL embedd...
β€17β‘6
WindRelay paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out.
https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
π8
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps
https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps
iverify.io
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
A previously undocumented Android on-device fraud bot, advertised as malware-as-a-service since June 2026, with overlays for crypto wallets and banking apps.
β‘5