Tag: mobile
All entries tagged mobile.
- This week's tradecraft was built against the analyst's environment, not the endpoint agent — samples that refuse to run without a keyed argument, loaders that cannot decrypt away from the host they infected, and operators driving the victim's own logged-in session
- CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
- RedHook Android RAT abuses ADB Wireless Debugging to self-grant shell (uid 2000) privileges without an exploit
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out
- FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover
- Research: usbliter8 — an unpatchable SecureROM boot-chain exploit for Apple A12/A13 silicon
- usbliter8 — a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- Meta files contempt complaint against NSO Group over fresh WhatsApp spyware phishing
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off
- Enclave: a single debug flag left on in six Microsoft 365 Android apps allowed silent OAuth-token theft
- CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation
- Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-days
- "Signal Support" impersonation phishing harvests cloud-backup recovery keys from high-value users
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164 — LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- Finance — Iberian retail-banking pressure from Grandoreiro plus a parallel Android MaaS
- TrickMo "TrickMo C" — Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- SMS-blaster smishing establishing itself in Switzerland — portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering