Cybersecurity News
Filters
Filtered by tag: mobile security × Clear
Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network
Kaspersky discovered Android malware targeting DoFun car head units by hijacking the TWCore update app to install malicious APKs. The multi-stage attack deploys a dropper, loader, and reverse proxy tool, with the apparent goal of building a botnet from internet-connected vehicles. Kaspersky attributed the campaign to MoYu Group, previously linked to the BadBox botnet. DoFun has since patched the vulnerabilities.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Matched: cryptocurrency
Manic is Android malware targeting Ukrainian and European banks, government services, cryptocurrency platforms, and military communications. It blends banking malware with spyware capabilities and can exfiltrate data from offline phones by routing it through nearby infected devices. The malware targets financial credentials, identity data, and messaging apps, representing an unusually sophisticated cross-sector mobile threat.
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Matched: cryptocurrency
ToxicPanda malware has been updated with 167 remote commands and expanded global targeting, according to Zimperium zLabs. The Android banking trojan now includes PIN harvesting capabilities targeting over 140 banking and cryptocurrency apps. Researchers also noted connections to the GoldDigger malware family, with both conducting on-device fraud to bypass traditional security measures.
'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers
Researchers warn that "Proactive SIM" cards can exploit a decades-old telecom standard to execute commands on host devices without user interaction. The vulnerability affects smartphones, IoT devices, and EV chargers. Because the SIM sits inside the device and communicates directly with its processor, a compromised or malicious card can run code invisibly, and researchers say discovered attacks likely represent only a fraction of what's possible.
Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes
Cybercriminals are targeting Android users with malware called WindRelay, which can clone contactless payment cards in around 13 minutes. Attackers phone victims, trick them into installing the malicious app, then use it to capture card data via the phone's NFC chip. The stolen information is relayed to a criminal-controlled device to make fraudulent payments.
