threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment systems, utilizing a sophisticated delivery method through the head unit's update functionality. The m… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel ToxicPanda Banking Trojan Matures into Enterprise Threat ToxicPanda, a banking Trojan, has evolved into a more sophisticated enterprise threat, expanding its reach beyond individual banking apps to compromise entire Android devices and potentially access corporate resources. T… Dark Reading · 6d ago High LAITPObankingmobileenterprise
threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
threat-intel Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Multiple banking trojans – Manic, Grandoreiro, and ToxicPanda 2.0 – are actively targeting users worldwide, with a particular focus on financial institutions in Europe, Latin America, and increasingly, Russia. These troj… SecurityWeek · Aug 22, 2026 High BRUKRUbanking trojanmobile malwaresupply chain
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel The invisible passenger in your car Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system u… Securelist · Aug 21, 2026 High androidiotbotnet
threat-intel Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Manic, a sophisticated Android malware, is actively targeting financial institutions and government services across Ukraine, Russia, Central and Western Europe, and the U.K. This malware combines banking malware capabili… The Hacker News · Aug 20, 2026 High UKRUCEandroidbanking malwarespyware
threat-intel Video Call Exploit Chains Two Flaws in Unisoc Modems Researchers at SSD Secure Disclosure have discovered a new exploit chain targeting Unisoc T612 modems, allowing attackers to gain kernel-level access on Android devices. The vulnerability combines a previously disclosed… Dark Reading · Aug 17, 2026 High CHcellularmodemandroid
vulnerability Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Security researchers at SSD Secure Disclosure have discovered a two-stage exploit chain that allows attackers to gain full Android kernel access on devices using Unisoc modem firmware. The vulnerability stems from a shar… The Hacker News · Aug 17, 2026 High CVE-2025-31718CVE-2022-20210CHandroidmodemkernel
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
vulnerability Mira Hormone Monitor, Mira Android App Multiple vulnerabilities in the Mira Hormone Monitor and Mira Android App allow an attacker to access unauthorized health profile information, make changes to health data, cause denial-of-service conditions, and potentia… CISA Advisories · Aug 11, 2026 High CVE-2026-66875CVE-2026-66098CVE-2026-67558bleauthenticationwebview
threat-intel IT threat evolution in Q2 2026. Mobile statistics In Q2 2026, mobile malware attacks continued to decline, with Trojan-Banker applications representing the most prevalent threat. Despite a drop in new Trojan variants, the landscape remained dominated by Mamont banking T… Securelist · Aug 10, 2026 Medium mobilemalwarebanking
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
vulnerability Multiples vulnérabilités dans Google Pixel (05 août 2026) Google has discovered and addressed multiple vulnerabilities within its Pixel devices. These vulnerabilities could allow an attacker to gain elevated privileges, though specific details remain undisclosed. Users are advi… CERT-FR · Aug 5, 2026 Medium CVE-2026-0163androidsecurityvulnerability
vulnerability Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026) Mozilla has announced a vulnerability in Firefox for Android that could allow an attacker to compromise user data confidentiality. Users running versions of Firefox for Android prior to 153.0.3 are at risk and should upd… CERT-FR · Aug 5, 2026 Medium CVE-2026-18809firefoxandroidvulnerability
vulnerability Multiples vulnérabilités dans Google Android (04 août 2026) Google Android is experiencing multiple vulnerabilities, as reported by CERT-FR. The exact nature of these vulnerabilities is not specified, but users are urged to apply the security patch released on August 3, 2026, to… CERT-FR · Aug 4, 2026 Medium androidvulnerabilitysecurity
threat-intel Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies A Chinese company, Zhejiang Fengwo IoT Technology Co., Ltd., is behind the ‘Fuyao’ operation, which involves shipping cheap Android TV boxes with apps that mimic phones and then use them to relay internet traffic as SOCK… The Hacker News · Jul 31, 2026 High CHHOSIandroidad fraudsocks5
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud