Android
Android security: mobile malware, device compromises and platform vulnerabilities. Follow attack methods, affected devices and protection guidance.
Latest report:
Matching reports 14
RemControl Turns Fake IPTV Downloads Into Full Android Banking Surveillance
RemControl Android malware spreads via fake TVTap IPTV pages, stealing banking credentials with overlays, surveillance and remote control.
RatHat Turns Android’s Own Debugging Tools and Generative AI Into a Persistent Control Channel
RatHat Android malware abuses Accessibility to enable wireless ADB, persist via reverse proxy, and use AI for screen navigation and banking theft.
Claude-Assisted Operation Scanned 1.8 Million Android Apps for Exposed Secrets
Hackers used Claude AI to scan 1.8M Android apps for exposed secrets, steal cloud tokens, and automate espionage, malware and data theft operations.
GoldFactory Clones Android Banking Apps to Evade Fraud Controls in Indonesia
GoldFactory uses Gigabud and Vwork to clone Indonesian banking apps inside Android Work Profiles, evading fraud controls and causing $1M losses.
Deceptive Android Apps Exploit Google Play Early Access to Hide User Warnings
Thousands of deceptive Android applications are abusing Google Play’s Early Access program to attract installs without exposing users to public reviews or
Mantax Otax Android Malware Encrypts Files, Spies on Victims, and Weaponizes Harassment
Mantax Otax Android malware encrypts files on Android 9 or older, steals SMS, screen data, and harasses victims. Distributed via APKs outside Google Play.
WeChat Zero-Click Worm Hijacked Accounts Through Incoming Calls
A zero-click WeChat flaw let contacts hijack accounts via incoming calls and spread as a worm. Fixed in August updates with server-side blocking.
StreamRat, the Android Trojan Spread Through Fake Streaming Ads on Meta
StreamRat is an Android trojan spread via fake streaming ads on Meta targeting Spain, using a dropper APK and Accessibility abuse for remote control.
ToxicPanda 2.0 Abuses VPN to Block Google Play and Control Android Smartphones
Discover how ToxicPanda 2.0 malware exploits VPN permissions to block Google Play, steal banking credentials, and take control of Android smartphones.
Manic: The Android Malware Creating a Mesh Network to Steal Data Offline
Discover how Manic Android malware uses accessibility services and a store-and-forward mechanism to steal data offline via device-to-device mesh networks.
Malware in Android Car Head Units: Updates Become a Channel for Ad Fraud and Proxy Botnets
Malware exploits Android car head unit updates for ad fraud and proxy botnets, turning vehicles into compromised network nodes.
Unisoc Modems: A VoLTE Attack Chain Can Reach the Android Kernel
Discover how a Unisoc modem vulnerability allows attackers to gain Android kernel access through a VoLTE video call. Affects chipsets like T606, T612, T7250.
How this coverage is selected
Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.











