Skip to content

Topic

Android Malware

Malicious Android applications, including remote access trojans and second-stage payloads installed on victim devices.

Current stories

security3 publishers

Card-present fraud without the card: WindRelay relays NFC from the victim's own phone

Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 63%
Investor
Investor 10%

Reality

Evidence62
Adoption20
Hype gap+10
Incentives40
Confidence65
security4 publishers

Manic's fallback channel: Android malware that exfiltrates through the phone next to yours

ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.

Publishers:bleepingcomputer.comsecurityaffairs.comthehackernews.comthreatfabric.com

Perspective Coverage

4 publishers
Builder
Builder 36%
Operator
Operator 58%
Investor
Investor 6%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence68
security8 publishers

The firmware updater in the dashboard: car head units enrolled into a proxy botnet

Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.

Perspective Coverage

8 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence68
security3 publishers

Gigabud creates an Android work profile to put its fake bank app out of the scanner's reach

Group-IB says a second app sets up the work profile within minutes of infection and clones a fake bank app into it, so the malware check inside that app looks at an empty room while the trojan runs in the personal space.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%

Reality

Evidence55
Adoption30
Hype gap+15
Incentives50
Confidence60
security6 publishers

RatHat self-pairs Android's debug bridge to survive its own uninstall

Zimperium says RatHat uses an accessibility grant to switch on Wireless Debugging and read its own 6-digit pairing code, leaving native daemons at shell privilege that keep answering after the app is removed.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence62
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence66