Category: Mobile
-
BTMOB Android malware service generates custom phishing payloads
BTMOB Android malware service generates custom phishing payloads An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. […] Bill Toulas Go to bleepingcomputer
-
ScarCruft hackers push BirdCall Android malware via game platform
ScarCruft hackers push BirdCall Android malware via game platform The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform. […] Bill Toulas Go to bleepingcomputer
-
Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions
Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of…
-
NGate Android malware uses HandyPay NFC app to steal card data
NGate Android malware uses HandyPay NFC app to steal card data A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. […] Bill Toulas Go to bleepingcomputer
-
China’s Apple App Store infiltrated by crypto-stealing wallet apps
China’s Apple App Store infiltrated by crypto-stealing wallet apps A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […] Bill Toulas Go to bleepingcomputer
-
Google adds ‘Advanced Flow’ for safe APK sideloading on Android
Google adds ‘Advanced Flow’ for safe APK sideloading on Android Google has announced a new mechanism in Android called Advanced Flow that will allow sideloading APKs from unverified developers for power users in a more secure way. […] Bill Toulas Go to bleepingcomputer
-
New BeatBanker Android malware poses as Starlink app to hijack devices
New BeatBanker Android malware poses as Starlink app to hijack devices A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
Predator spyware hooks iOS SpringBoard to hide mic, camera activity
Predator spyware hooks iOS SpringBoard to hide mic, camera activity Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. […] Bill Toulas Go to bleepingcomputer
-
PromptSpy is the first known Android malware to use generative AI at runtime
PromptSpy is the first known Android malware to use generative AI at runtime Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google’s Gemini model to adapt its persistence across different devices. […] Lawrence Abrams Go to bleepingcomputer
-
Hugging Face abused to spread thousands of Android malware variants
Hugging Face abused to spread thousands of Android malware variants A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services. […] Bill Toulas Go to bleepingcomputer
-
Cellik Android malware builds malicious versions from Google Play apps
Cellik Android malware builds malicious versions from Google Play apps A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground cybercrime forums offering a robust set of capabilities that include the option to embed it in any app available on the Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
New DroidLock malware locks Android devices and demands a ransom
New DroidLock malware locks Android devices and demands a ransom A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data. […] Bill Toulas Go to bleepingcomputer
-
State-backed spyware attacks are targeting Signal and WhatsApp users, CISA warns
State-backed spyware attacks are targeting Signal and WhatsApp users, CISA warns CISA, the US Cybersecurity and Infrastructure Security Agency, has issued a new warning that cybercriminals and state-backed hacking groups are using spyware to compromise smartphones belonging to users of popular encrypted messaging apps such as Signal, WhatsApp, and Telegram. Read more in my article…
-
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop Google has added interoperability support between Android Quick Share and Apple AirDrop, to let users share files between Pixel devices and iPhones. […] Bill Toulas Go to bleepingcomputer
-
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages A new Android banking trojan named Sturnus can capture communication from end-to-end encrypted messaging platforms like Signal, WhatsApp, and Telegram, as well as take complete control of the device. […] Bill Toulas Go to bleepingcomputer
-
Google to flag Android apps with excessive battery use on the Play Store
Google to flag Android apps with excessive battery use on the Play Store Google will start taking action on Android apps in the official Google Play store that have high background activity and cause excessive battery draining. […] Bill Toulas Go to bleepingcomputer
-
New LandFall spyware exploited Samsung zero-day via WhatsApp messages
New LandFall spyware exploited Samsung zero-day via WhatsApp messages A threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware called ‘LandFall’ using malicious images sent over WhatsApp. […] Bill Toulas Go to bleepingcomputer
-
Malicious Android apps on Google Play downloaded 42 million times
Malicious Android apps on Google Play downloaded 42 million times Hundreds of malicious Android apps on Google Play were downloaded more than 40 million times between June 2024 and May 2025, notes a report from cloud security company Zscaler. […] Bill Toulas Go to bleepingcomputer
-
Massive surge of NFC relay malware steals Europeans’ credit cards
Massive surge of NFC relay malware steals Europeans’ credit cards Near-Field Communication (NFC) relay malware has grown massively popular in Eastern Europe, with researchers discovering over 760 malicious Android apps using the technique to steal people’s payment card information in the past few months. […] Bill Toulas Go to bleepingcomputer
-
Spam text scammer fined £200,000 for targeting people in debt, after sending nearly one million messages
Spam text scammer fined £200,000 for targeting people in debt, after sending nearly one million messages The UK Information Commissioner’s Office (ICO) has levied a fine of £200,000 against a sole trader who sent almost one million spam text messages to people across the country – many of whom were already struggling with debt. Read…
-
New Android Pixnapping attack steals MFA codes pixel-by-pixel
New Android Pixnapping attack steals MFA codes pixel-by-pixel A new side-channel attack called Pixnapping enables a malicious Android app with no permissions to extract sensitive data by stealing pixels displayed by applications or websites, and reconstructing them to derive the content. […] Bill Toulas Go to bleepingcomputer
-
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube A new Android spyware called ClayRat is luring potential victims by posing as popular apps and services like WhatsApp, Google Photos, TikTok, and YouTube. […] Bill Toulas Go to bleepingcomputer
-
Android malware uses VNC to give attackers hands-on access
Android malware uses VNC to give attackers hands-on access A new Android banking and remote access trojan (RAT) dubbed Klopatra disguised as an IPTV and VPN app has infected more than 3,000 devices across Europe. […] Bill Toulas Go to bleepingcomputer
-
Your favourite phone apps might be leaking your company’s secrets
Your favourite phone apps might be leaking your company’s secrets Most of the apps on your phone are talking to a server somewhere – sending and receiving data through messages sent through APIs, the underlying infrastructure that allows apps to communicate. And here’s the problem – hackers have determined that the APIs of mobile apps,…
-
Unpatched flaw in OnePlus phones lets rogue apps text messages
Unpatched flaw in OnePlus phones lets rogue apps text messages A vulnerability in multiple OnePlus OxygenOS versions allows any installed app to access SMS data and metadata without requiring permission or user interaction. […] Bill Toulas Go to bleepingcomputer
-
Pixel 10 fights AI fakes with new Android photo verification tech
Pixel 10 fights AI fakes with new Android photo verification tech Google is integrating C2PA Content Credentials into the Pixel 10 camera and Google Photos, to help users distinguish between authentic, unaltered images and those generated or edited with artificial intelligence technology. […] Bill Toulas Go to bleepingcomputer
-
Google to verify all Android devs to block malware on Google Play
Google to verify all Android devs to block malware on Google Play Google is introducing a new defense for Android called ‘Developer Verification’ to block malware installations from sideloaded apps sourced from outside the official Google Play app store. […] Bill Toulas Go to bleepingcomputer
-
Malicious Android apps with 19M installs removed from Google Play
Malicious Android apps with 19M installs removed from Google Play Seventy-seven malicious Android apps containing different types of malware were found on Google Play after being downloaded more than 19 million times. […] Bill Toulas Go to bleepingcomputer
-
ERMAC Android malware source code leak exposes banking trojan infrastructure
ERMAC Android malware source code leak exposes banking trojan infrastructure The source code for version 3 of the ERMAC Android banking trojan has been leaked online, exposing the internals of the malware-as-a-service platform and the operator’s infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Smashing Security podcast #427: When 2G attacks, and a romantic road trip goes wrong
Smashing Security podcast #427: When 2G attacks, and a romantic road trip goes wrong Graham warns why it is high time we said goodbye to 2G – the outdated mobile network being exploited by cybercriminals with suitcase-sized SMS blasters. From New Zealand to London, scammers are driving around cities like dodgy Uber drivers, spewing phishing…
-
SIM scammer’s sentence increased to 12 years, after failing to pay back victim $20 million
SIM scammer’s sentence increased to 12 years, after failing to pay back victim $20 million Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
Google reveals details on Android’s Advanced Protection for Chrome
Google reveals details on Android’s Advanced Protection for Chrome Google is sharing more information on how Chrome operates when Android mobile users enable Advanced Protection, highlighting strong security improvements. […] Bill Toulas Go to bleepingcomputer
-
Samsung announces major security enhancements coming to One UI 8
Samsung announces major security enhancements coming to One UI 8 Samsung has announced multiple data security and privacy enhancements for its upcoming Galaxy smartphones running One UI 8, its custom user interface on top of Android. […] Bill Toulas Go to bleepingcomputer
-
New Android TapTrap attack fools users with invisible UI trick
New Android TapTrap attack fools users with invisible UI trick A novel tapjacking technique can exploit user interface animations to bypass Android’s permission system and allow access to sensitive data or trick users into performing destructive actions, such as wiping the device. […] Bill Toulas Go to bleepingcomputer
-
Smashing Security podcast #424: Surveillance, spyware, and self-driving snafus
Smashing Security podcast #424: Surveillance, spyware, and self-driving snafus A Mexican drug cartel spies on the FBI using traffic cameras and spyware — because “ubiquitous technical surveillance” is no longer just for dystopian thrillers. Graham digs into a chilling new US Justice Department report that shows how surveillance tech was weaponised to deadly effect. Meanwhile,…
-
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks AT&T has launched a new security feature called “Wireless Lock” that protects customers from SIM swapping attacks by preventing changes to their account information and the porting of phone numbers while the feature is enabled. […] Lawrence Abrams Go to bleepingcomputer
-
50 customers of French bank hit after insider helped SIM swap scammers
50 customers of French bank hit after insider helped SIM swap scammers French police have arrested a business student interning at the bank Société Générale who is accused of helping SIM-swapping scammers to defraud 50 of its clients. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley
-
When hackers become hitmen
When hackers become hitmen So, you think hacking is just about stealing information, extorting ransoms, or wiping out company data? The truth is, sometimes it’s about killing people too… Graham Cluley Go to grahamcluley
-
Google Cloud donates A2A AI protocol to the Linux Foundation
Google Cloud donates A2A AI protocol to the Linux Foundation Google Cloud has donated its Agent2Agent (A2A) protocol to the Linux Foundation, which has now announced a new community-driven project called the Agent2Agent Project. […] Bill Toulas Go to bleepingcomputer
-
Malware on Google Play, Apple App Store stole your photos—and crypto
Malware on Google Play, Apple App Store stole your photos—and crypto A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices. […] Bill Toulas Go to bleepingcomputer
-
Godfather Android malware now uses virtualization to hijack banking apps
Godfather Android malware now uses virtualization to hijack banking apps A new version of the Android malware “Godfather” creates isolated virtual environments on mobile devices to steal account data and transactions from legitimate banking apps. […] Bill Toulas Go to bleepingcomputer
-
Authorities Busted Ransomware Gang – Nine Laptops and 15 Mobile Devices Were Seized
Authorities Busted Ransomware Gang – Nine Laptops and 15 Mobile Devices Were Seized Thai law enforcement successfully dismantled a sophisticated ransomware operation during a coordinated raid at the Antai Holiday Hotel in central Pattaya on Monday, June 16, 2025. The operation resulted in the arrest of six Chinese nationals specifically tasked with distributing malicious links…
-
Smashing Security podcast #420: Fake Susies, flawed systems, and fruity fixes for anxiety
Smashing Security podcast #420: Fake Susies, flawed systems, and fruity fixes for anxiety A bizarre case of political impersonation, where Trump’s top aide Susie Wiles is cloned (digitally, not biologically — we think), and high-ranking Republicans start getting invitations to link up with “her” on Telegram to share their Trump pardon wishlists. Was it a…
-
Mobile carrier Cellcom confirms cyberattack behind extended outages
Mobile carrier Cellcom confirms cyberattack behind extended outages Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft ends Authenticator password autofill, moves users to Edge
Microsoft ends Authenticator password autofill, moves users to Edge Microsoft has announced that it will discontinue the password storage and autofill feature in the Authenticator app starting in July and will complete the deprecation in August 2025. […] Bill Toulas Go to bleepingcomputer
-
Russian army targeted by new Android malware hidden in mapping app
Russian army targeted by new Android malware hidden in mapping app A new Android malware has been discovered hidden inside trojanized versions of the Alpine Quest mapping app, which is reportedly used by Russian soldiers as part of war zone operational planning. […] Bill Toulas Go to bleepingcomputer
-
New Android malware steals your credit cards for NFC relay attacks
New Android malware steals your credit cards for NFC relay attacks A new malware-as-a-service (MaaS) platform named ‘SuperCard X’ has emerged, targeting Android devices via NFC relay attacks that enable point-of-sale and ATM transactions using compromised payment card data. […] Bill Toulas Go to bleepingcomputer
-
E-ZPass toll payment texts return in massive phishing wave
E-ZPass toll payment texts return in massive phishing wave An ongoing phishing campaign impersonating E-ZPass and other toll agencies has surged recently, with recipients receiving multiple iMessage and SMS texts to steal personal and credit card information. […] Bill Toulas Go to bleepingcomputer
-
Verizon Call Filter API flaw exposed customers’ incoming call history
Verizon Call Filter API flaw exposed customers’ incoming call history A vulnerability in Verizon’s Call Filter feature allowed customers to access the incoming call logs for another Verizon Wireless number through an unsecured API request. […] Bill Toulas Go to bleepingcomputer
-
New Crocodilus malware steals Android users’ crypto wallet keys
New Crocodilus malware steals Android users’ crypto wallet keys A newly discovered Android malware dubbed Crocodilus tricks users into providing the seed phrase for the cryptocurrency wallet using a warning to back up the key to avoid losing access. […] Bill Toulas Go to bleepingcomputer
-
Malicious Android ‘Vapor’ apps on Google Play installed 60 million times
Malicious Android ‘Vapor’ apps on Google Play installed 60 million times Over 300 malicious Android applications downloaded 60 million items from Google Play acted as adware or attempted to steal credentials and credit card information. […] Bill Toulas Go to bleepingcomputer
-
New North Korean Android spyware slips onto Google Play
New North Korean Android spyware slips onto Google Play A new Android spyware named ‘KoSpy’ is linked to North Korean threat actors who have infiltrated Google Play and third-party app store APKPure through at least five malicious apps. […] Bill Toulas Go to bleepingcomputer
-
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks The Electronic Frontier Foundation (EFF) has released a free, open-source tool named Rayhunter that is designed to detect cell-site simulators (CSS), also known as IMSI catchers or Stingrays. […] Bill Toulas Go to bleepingcomputer
-
Google expands Android AI scam detection to more Pixel devices
Google expands Android AI scam detection to more Pixel devices Google has announced an increased rollout of new AI-powered scam detection features on Android to help protect users from increasingly sophisticated phone and text social engineering scams. […] Bill Toulas Go to bleepingcomputer
-
Serbian police used Cellebrite zero-day hack to unlock Android phones
Serbian police used Cellebrite zero-day hack to unlock Android phones Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. […] Bill Toulas Go to bleepingcomputer
-
SpyLend Android malware downloaded 100,000 times from Google Play
SpyLend Android malware downloaded 100,000 times from Google Play An Android malware app called SpyLend has been downloaded over 100,000 times from Google Play, where it masqueraded as a financial tool but became a predatory loan app for those in India. […] Bill Toulas Go to bleepingcomputer
-
Google Play, Apple App Store apps caught stealing crypto wallets
Google Play, Apple App Store apps caught stealing crypto wallets A new campaign dubbed ‘SparkCat’ has been uncovered, targeting the cryptocurrency wallet recovery phrases of Android and iOS users using optical character recognition (OCR) stealers. […] Bill Toulas Go to bleepingcomputer
-
Google blocked 2.36 million risky Android apps from Play Store in 2024
Google blocked 2.36 million risky Android apps from Play Store in 2024 Google blocked 2.3 million Android app submissions to the Play Store in 2024 due to violations of its policies that made them potentially risky for users. […] Bill Toulas Go to bleepingcomputer
-
New Android Identity Check locks settings outside trusted locations
New Android Identity Check locks settings outside trusted locations Google has announced a new Android “Identity Check” security feature that lock sensitive settings behind biometric authentication when outside a trusted location. […] Bill Toulas Go to bleepingcomputer
-
Allstate car insurer sued for tracking drivers without permission
Allstate car insurer sued for tracking drivers without permission Texas Attorney General Ken Paxton has filed a lawsuit against Allstate and its data subsidiary Arity for unlawfully collecting, using, and selling driving data from over 45 million Americans. […] Bill Toulas Go to bleepingcomputer
-
New FireScam Android data-theft malware poses as Telegram Premium app
New FireScam Android data-theft malware poses as Telegram Premium app A new Android malware named ‘FireScam’ is being distributed as a premium version of the Telegram app via phishing websites on GitHub that mimick the RuStore, Russia’s app market for mobile devices. […] Bill Toulas Go to bleepingcomputer
-
New EagleMsgSpy Android spyware used by Chinese police, researchers say
New EagleMsgSpy Android spyware used by Chinese police, researchers say A previously undocumented Android spyware called ‘EagleMsgSpy’ has been discovered and is believed to be used by law enforcement agencies in China to monitor mobile devices. […] Bill Toulas Go to bleepingcomputer
-
SpyLoan Android malware on Google play installed 8 million times
SpyLoan Android malware on Google play installed 8 million times A new set of 15 SpyLoan Android malware apps with over 8 million installs was discovered on Google Play, targeting primarily users from South America, Southeast Asia, and Africa. […] Bill Toulas Go to bleepingcomputer