ZeroHour
Product

Android

10 mentions in 7 days · 18 in 30 days · 18 total · first seen · last

Timeline

Android malware creates a hidden copy of your banking app

Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.

Group-IB researchers found the Gigabud Android banking trojan installs Vwork, a trojanized version of the open-source Shelter app, to create a separate Android work profile and clone the victim's banking app into it. The operator then performs fraudulent transactions from the cloned app, separating risky activity from malware detections in the personal profile and potentially bypassing bank-side anti-fraud checks. Victims are lured into sideloading fake airline, tax, or government apps via phishing sites and messages, then grant Accessibility, overlay, and battery-optimization permissions that enable remote control and credential-theft overlays. Malwarebytes detects Gigabud components under multiple Android.Trojan.Banker signatures.

Malwarebytes Labs · 4d agoMalware 6 sources

New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.

Zimperium reported a new Android threat, Mantax Otax, that combines ransomware with surveillance: it encrypts files with AES and adds a .enc extension on Android 9 and older, while abusing MediaProjection for screenshots and MP4 screen recording and using hidden camera previews to photograph victims. The malware intercepts SMS one-time passwords, WhatsApp and Telegram data, and lock-screen PINs through Accessibility abuse and a fake system-lock overlay, and can negotiate ransoms via an on-screen chat. Malicious APKs are hosted on third-party file-sharing services, and researchers linked the activity to Indonesian threat actors, with C2 dynamically retrieved from a GitHub repository (apimantax[.]otax[.]fun). A second variant adds WebSocket communications, app blocking, full-screen overlays, and remote text-to-speech messages.

Cyber Security News · 4d agoRansomware 6 sources

Indonesia Hit by Android Banking App-Cloning Campaign

GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.

The GoldFactory threat group is running an app-cloning campaign against Android banking customers in Indonesia, abusing the Android Work Profile feature to deliver its Gigabud trojan. The Mantax and Otax malware families are spreading through separate distribution channels. Abusing Work Profile to install or conceal cloned banking apps is a notable mobile technique, though the article reports no victim counts or loss figures.

Dark Readingupdated · 4d agofirst · 4d agoThreat actor in the wild 6 sources

New Android malware encrypts files, steals data, and harasses victims

Zimperium details Mantax Otax, an Android malware combining ransomware, spyware, and harassment, spread via phishing APKs to Indonesian users.

Zimperium researchers report Mantax Otax is distributed through malicious APKs hosted outside Google Play via phishing and social engineering, then abuses Accessibility permissions for broad device control. It encrypts files with a C2-provided AES key on Android 9 and older, adds '.enc' extensions, and hosts ransom chats on Firebase; researchers exposed attacker chats via a Firebase misconfiguration. The malware steals lock-screen PINs, SMS one-time codes, contacts, WhatsApp and Telegram chats, and captures screens via MediaProjection, while version 2 adds jumpscare overlays and text-to-speech harassment. Google Play Protect already detects and blocks it on up-to-date devices via the App Defense Alliance.

BleepingComputerupdated · 4d agofirst · 4d agoMalware in the wild 6 sources

Your passkeys can now move between password managers on Android

Google enabled direct password and passkey transfers between Android password managers, initiated from the destination app without unencrypted file exports.

Android now supports moving passwords and passkeys directly between password managers without exporting them to a file, replacing the previous unencrypted-export workflow. The transfer is initiated in the receiving app, which hands off to Android to detect installed managers and request authorization in the source app. The feature works today with Google Password Manager, 1Password, Bitwarden, and Dashlane, with more partners promised but unnamed. Google says data moves between apps in seconds and calls the handoff secure, without detailing the protections.

Help Net Security · 5d agoTools

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Group-IB reports the Gigabud Android banking trojan uses a cloned work profile to hide from banking app malware checks, with infections confirmed in Indonesia.

Group-IB says Gigabud installs a helper app called Vwork, derived from the open-source Shelter tool, which creates an Android work profile and drops a tampered banking app inside it, hiding the trojan from banking apps' malware scans. Gigabud, active since 2022 and linked by Group-IB to the GoldFactory group, abuses Accessibility access and overlay screens to steal credentials and run fraudulent payments while a black screen conceals the operator's actions. Group-IB confirmed the full attack chain on infected devices in Indonesia, counting about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026. Vwork-compatible Gigabud samples have been found targeting 11 countries including Brazil, Mexico, Indonesia, Thailand, and Türkiye, though only the Indonesian chain is confirmed.

The Hacker Newsupdated · 4d agofirst · 5d agoMalware in the wild 6 sources1

JarvisGUI: Towards Cross-Device GUI Agents with Dynamic Task Composition

JarvisGUI benchmark tests GUI agents on cross-device workflows across Android, Windows, and Ubuntu, revealing major gaps in state transfer and long-horizon reasoning.

JarvisGUI is a dynamic benchmark that formulates GUI tasks as input-output transformations under a lightweight type system, automatically composing multi-step cross-device workflows across Android, Windows, and Ubuntu virtual environments. Evaluation shows state-of-the-art open-source GUI agents struggle with state-transfer awareness, cross-platform contextual reasoning, and long-horizon dependency management, exposing a capability gap invisible to existing single-device benchmarks.

arXiv cs.AI / cs.LG / cs.CL · 6d agoAI research1

Android’s September 2026 Updates Patch 180 Vulnerabilities

Google's September 2026 Android security updates patch 180 vulnerabilities including critical Wi-Fi memory corruption flaw CVE-2026-28662.

Google released September 2026 Android security updates addressing 180 vulnerabilities across two patch levels. The 2026-09-01 level fixes 95 bugs including 23 critical System component flaws enabling RCE, EoP, and DoS. The 2026-09-05 level addresses 85 additional defects in kernel and vendor components including a Wi-Fi memory corruption flaw (CVE-2026-28662) enabling remote code execution without privileges or user interaction.

SecurityWeek · 6d agoAdvisoryCVE-2026-28662

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

Group-IB says GoldFactory's Gigabud Android trojan uses Vwork, a weaponized Shelter fork, to clone banking apps into isolated Work Profiles and evade bank-side detection.

Group-IB's 'Hook for Gold' investigation found GoldFactory ships Vwork, a modified fork of the open-source Shelter app, alongside its Gigabud Android banking trojan, active since 2022. Vwork abuses Android Work Profile provisioning to clone banking apps into an isolated environment, weakening the link between detected malware signals and fraudulent transactions. Gigabud has targeted victims in Southeast Asia, Latin America, the Middle East, Africa, and beyond via fake airline, tax, and government apps requesting Accessibility and overlay permissions. In Indonesia, telemetry recorded about 1,469 compromised devices and roughly $960,939 in estimated losses between February and July 2026.

GBHackersupdated · 4d agofirst · 6d agoMalware in the wild 6 sources

WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android

Researchers demonstrated WeWorm, a zero-click worm exploiting a memory-corruption flaw in WeChat's VoIP stack to spread via calls across iOS and Android.

Security firm Calif published WeWorm, a proof-of-concept zero-click worm exploiting a memory-corruption bug in WeChat's VoIP stack to spread through voice calls on iOS and Android without the victim answering. The demo chained a Pixel 10a, an iPhone 17e, and a second Pixel 10a, compromising each device while the call was still ringing and giving full control of the WeChat account. The attacker must already be on the victim's friend list, but compromised contacts become the propagation layer across a platform with over 1.4 billion monthly users. Calif reported the bug to Tencent in July 2026, and Tencent has since mitigated it; full technical details are withheld for a later conference presentation.

Cyber Security News · 7d agoExploit / PoC

THost9 Android RAT Pairs Packed Loader With ADB Worm

Dark Atlas details THost9, a packed Android RAT paired with an ADB worm that installs itself on devices with exposed Android Debug Bridge services.

Dark Atlas researchers described the Hagaseca cluster, whose THost9 packed loader hides executable code in an embedded asset decoded with single-byte XOR and gzip before loading a tc9.dex second stage. The second stage adds shell execution, file transfer, tunneling, reverse shells, downloadable modules and a self-propagating ADB worm that expands single addresses into 65,025-host scan ranges. Newer builds include anti-analysis checks for Frida, and incident reports connect THost9 and THost4 to Android phones and Redroid containers with exposed ADB from October 2024 through 2026.

Infosecurity Magazine · 7d agoMalware in the wild

GrapheneOS Overhauled Default Apps and Secure Clipboard

GrapheneOS announced an overhaul of its default apps and a redesigned secure clipboard in its privacy-focused Android distribution.

The GrapheneOS project posted on Mastodon that it has "overhauled default apps and secure clipboard" in its privacy and security hardened Android OS. The provided text contains only the announcement title and engagement figures, without release notes or technical specifics. Changes to built-in apps and clipboard handling in GrapheneOS are typically relevant to Android privacy and mobile security practitioners.

Your phone or computer may soon ask how old you are

California's Digital Age Assurance Act forces Windows, macOS, iOS, and Android to collect age brackets from January 2027, with open-source exemptions pending.

California's Digital Age Assurance Act, signed in October 2025, requires major operating systems to collect user age brackets (under 13, 13-15, 16-17, 18+) and share non-identifying age signals with app developers starting January 1, 2027, with existing setups complying by July 1, 2027. AB1856, passed in late August 2026, would exempt open-source operating systems under GPL, MIT, BSD, and Apache licenses and awaits the governor's signature. Colorado, Illinois, and New York have similar age assurance measures, and the EFF has criticized the law for privacy and censorship concerns.

Malwarebytes Labs · 12d agoPolicy & legal

Android Malware Hijacks Update System for Car Head Units

A click-fraud botnet crew now deploys Android malware to car head-unit infotainment systems by abusing the legitimate software update mechanism.

Threat actors behind a notorious Android click-fraud botnet are targeting vehicle infotainment head units, according to Dark Reading. The malware abuses legitimate update functionality to install and spread infections. The campaign highlights automotive Android systems as an emerging attack surface for established mobile botnet operators.

Dark Reading · 20d agoMalware in the wild

Hackers infecting Android car systems to build proxy botnet

Kaspersky reports MoYu Group-linked malware infecting DoFun Android car head units, enrolling them in a BadBox-linked proxy botnet for ad fraud and traffic routing.

Kaspersky discovered malware on Android-based head units made by Chinese automotive supplier DoFun, the first documented case of a car head unit being infected through an attack purpose-built for such devices. Attackers abused TWCore, a legitimate DoFun system application that handles updates and can install new apps, to silently push a malicious app called JarService that displays ads, generates fraudulent ad clicks and downloads additional malware. One malware module turns infected head units into reverse proxies so other users' internet traffic can be routed through the car's connection. Kaspersky attributes the campaign with high confidence to MoYu Group, linked to the BadBox operation, which previously infected over 70,000 Android devices and resurfaced as BadBox 2.0 after German authorities disrupted the original botnet in December 2024.

The Record · 22d agoMalware in the wild

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

ThreatFabric identified Manic, an Android banking malware and spyware targeting Ukrainian and European financial apps with novel offline Wi-Fi mesh data exfiltration via nearby infected devices.

ThreatFabric reported a new Android malware family called Manic combining banking fraud and surveillance capabilities, targeting 169 package IDs across Ukrainian banks, government and identity services, messaging apps, and Russian and European financial institutions. The malware uses phishing sites and dropper apps impersonating utilities for distribution and relies on accessibility services and notification permissions for keylogging, overlays, and remote control. It introduces a store-and-forward relay mechanism that stages encrypted data locally and relays it through nearby infected devices via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, supporting up to four hops when the primary device lacks internet access. Activity dates back to February 2026, with active development through late July.

The Hacker News · 25d agoMalware in the wild

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Unisoc modem firmware flaw CWE-1189 allows VoLTE video call RCE chain to gain full Android kernel access on T606/T612/T7250 chipsets; no patch yet.

SSD Secure Disclosure published the second stage of an exploit chain, first disclosed in March 2026, that achieves full Android kernel access on Unisoc modem firmware via a VoLTE video call. The privilege-escalation flaw, classified as CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip), exploits shared physical memory between modem and application processor with no hardware boundary, letting modem code map the entire 32-bit address space and modify Android kernel pages via ARM Memory Protection Unit registers. Confirmed affected chipsets include Unisoc T606 (Motorola E13), T612 (Realme C33), and T7250 (Xiaomi Redmi A5), sold across more than 140 countries. No CVE has been assigned, the August 2026 Android Security Bulletin does not address it, and Unisoc has not responded to researchers; exploitation requires an attacker-controlled private 4G network and a victim answering the call.

Related CVEs

  • Heap Buffer Overflow in Android Wi-Fi Direct (P2P) Provisioning Discovery Enables Nearby RCE
    CVE-2026-28662 is a heap buffer overflow causing an out-of-bounds write in p2p_process_prov_disc_bootstrap_req in p2p_pd.c, the code that handles Wi-Fi P2P (Wi-Fi Direct) provisioning discovery bootstrap requests in Android's Wi-Fi stack. It is triggered when a nearby attacker sends a crafted bootstrap request over the air while the device's Wi-Fi is enabled; no user interaction or privileges are required. Successful exploitation yields remote (proximal/adjacent) code execution, meaning anyone within Wi-Fi radio range could run code on the device. Android devices running software prior to the September 2026 Android Security Update are affected. Exploitation is not currently observed: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.1%.
    · Google / Android (CNA: [email protected]) Android OS Wi-Fi P2P (Wi-Fi Direct) stack, p2p_process_prov_disc_bootstrap_req in p2p_pd.cmass
  • Out-of-bounds write via integer overflow in Android NFC stack enables RCE
    CVE-2026-49879 is an integer overflow in Android's NFC reader/writer code (rw_t3t.cc, the component that handles NFC Type 3/FeliCa tags) that results in an out-of-bounds write when the stack processes crafted tag data. An attacker can trigger it by getting the device to process malicious NFC data — most plausibly a nearby malicious NFC tag — with no user interaction and no special privileges required. Successful exploitation yields remote code execution in the context of the NFC service, though no public proof-of-concept or in-the-wild exploitation is currently known. Any Android device with NFC hardware is potentially affected, with the fix delivered through the September 2026 Android Security Update. EPSS currently estimates only a 0.2% probability of exploitation within 30 days and the flaw is not yet in CISA's KEV catalog.
    · Google / Android Android OS NFC stack (rw_t3t.cc, Type 3 tag handling)mass
  • Heap Buffer Overflow in Android NFC MIFARE Classic Reader Enables RCE
    CVE-2026-49882 is a heap buffer overflow in rw_mfc_handle_read_op (rw_mfc.cc), part of the Android NFC stack's handling of MIFARE Classic (MFC) tags. An attacker within NFC range can trigger the flaw by presenting a maliciously crafted MIFARE Classic tag to a device whose NFC reader processes it, with no user interaction and no privileges required. Successful exploitation can lead to remote code execution on the affected device. Android devices carrying the vulnerable NFC code are affected; the data does not specify exact version ranges, and the fix ships in the September 2026 Android security update per related reporting. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it a low 0.2% probability of exploitation in the next 30 days, so no exploitation is known.
    · Google (Android) Android NFC stack, MIFARE Classic tag handling (rw_mfc.cc)mass
  • Remote DoS/RCE in Android image resolver via DNG rendering check bypass
    CVE-2026-28666 is a flaw in LocalImageResolver.java in the Android platform's image-handling code, where a DNG (Digital Negative) image rendering check can be bypassed. The Android security team classifies the issue as a remote persistent denial of service, but notes it could also lead to remote escalation of privilege, requiring no additional execution privileges and no user interaction. An attacker could trigger the flaw by getting a crafted DNG image processed by an affected device, degrading the device persistently or, per the bulletin, gaining elevated code execution. The flaw affects the Android platform component (assigned by [email protected]), so any Android device shipping the vulnerable image-resolution code is potentially exposed, pending OEM patches. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
    · Google / Android (AOSP) Android platform image handling component (LocalImageResolver.java, DNG rendering)mass
  • Use-after-free local privilege escalation in Android (Linux kernel KVM IOMMU)
    CVE-2026-58846 is a use-after-free in the kvm_iommu_map_sg function (iommu.c) of the KVM IOMMU code in the Android Linux kernel, caused by a missing permission check (CWE-269). A local attacker can reach the vulnerable scatter-gather mapping path and trigger the flaw without user interaction and with no additional execution privileges. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected parties are users of Android devices running vulnerable kernel builds; Google shipped the fix in the September 2026 Android Security Update. There is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.1% probability of exploitation within 30 days, so no exploitation is currently known.
    · Google (Android) Android OS (Linux kernel, KVM IOMMU — kvm_iommu_map_sg in iommu.c)mass
  • Out-of-Bounds Write in Android NFC (MIFARE Classic) Allows Local Privilege Escalation
    CVE-2026-28639 is an out-of-bounds write in rw_mfc_handle_read_op (rw_mfc.cc), the handler for MIFARE Classic tag read operations in the Android NFC stack, caused by a logic error in the code. It is triggered when the NFC subsystem processes MIFARE Classic read operations, and exploitation requires no user interaction and no additional execution privileges. A successful exploit corrupts adjacent memory and can lead to local escalation of privilege on the affected device. All Android devices running the vulnerable NFC code are affected; the flaw is addressed in the September 2026 Android Security Update. There is currently no public proof of concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.1%, so no exploitation is known.
    · Google / Android (CNA: [email protected]) Android OS — NFC subsystem (rw_mfc.cc, rw_mfc_handle_read_op)mass
  • Android OS Integer Overflow Enables Local Privilege Escalation
    CVE-2026-58820 is a memory safety vulnerability in the Android operating system in which integer overflow conditions in multiple code locations corrupt memory, classified as a heap-based buffer overflow (CWE-122). Triggering it requires only low-level local access, as the flaw can be exploited with no additional execution privileges, meaning an app or process already running on the device can potentially abuse it. Successful exploitation results in local escalation of privilege with high impact on confidentiality, integrity, and availability on the device; no remote or unauthenticated attack path is indicated by the CVSS vector. The available data does not specify which Android versions or components are affected, but the flaw was addressed in Google's September 2026 Android Security Update, so any device not yet running that patch level is plausibly exposed. There is no known public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS assigns only a 0.1% probability of exploitation within the next 30 days.
    · Google (Android) Android OSmass
  • Improper Encryption Key Validation Enables Local Privilege Escalation in Android
    CVE-2026-28590 is a local privilege escalation flaw in Android caused by a logic error that results in improper validation of encryption keys in multiple places in the code. It is triggered by code already running locally on the device, with no need for special execution privileges and no user interaction, so any app or process with local code execution could potentially exploit it. An attacker who exploits it gains elevated privileges on the affected device, which is most valuable as one link in a chained attack alongside other flaws (the September 2026 Android bulletin also fixed separate remote code execution issues). Affected parties are users of Android devices that have not yet received the September 2026 Android security update; the specific affected version ranges were not detailed in the available data. There is no known public proof of concept, it is not listed in CISA's Known Exploited Vulnerabilities catalog, and its current probability of exploitation within 30 days is estimated at 0.1%.
    · Google (Android) Android OS (multiple components; assigned by [email protected])mass
  • Local Privilege Escalation via Heap Overflow in Android fsck
    An out-of-bounds read caused by a heap buffer overflow exists in the read_boot_region function of fsck.c on Android. It can be triggered when the system's fsck tool processes a malformed or crafted filesystem boot region, with no user interaction and no additional execution privileges required. A successful exploit could allow a local attacker to escalate privileges on the affected device. All Android devices running security patch levels prior to the September 2026 Android Security Update are potentially affected. There is no public proof of concept, the flaw is not in CISA KEV, and EPSS is low (0.1%), indicating no known exploitation to date.
    · Google (Android) Android (fsck component, read_boot_region in fsck.c) Android devices on security patch levels before the September 2026 Android Security Update; fixed in the September 2026 update (specific affected version rangesmass
  • Remote Persistent Denial-of-Service in Android parsePartHeaders (CVE-2026-55256)
    CVE-2026-55256 is an improper input validation flaw in the parsePartHeaders routine of Android, which parses message part headers; malformed content processed by this parser can trigger a persistent denial of service. It can be triggered remotely, with no attacker privileges and no user interaction required, by delivering crafted data to the affected parsing code. An attacker gains a sustained, persistent denial-of-service condition on the affected device or component; no code execution, privilege escalation, or data exposure is described. Any Android build containing the vulnerable parsing code is affected, but the available data does not specify which Android versions or ranges are impacted. There is currently no known exploitation, no public proof of concept, a low predicted exploitation probability (EPSS 0.2%, 5th percentile), and the flaw is not in the CISA KEV catalog.
    · Google (Android / AOSP; CNA: [email protected]) Android - message part header parsing (parsePartHeaders, multiple files)mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.