#AndroidTrojan
India Orders Google to Remove 57 Firebase Sites Linked to Cyber Scams #AndroidTrojan #CyberFraud #GoogleFirebase
India Orders Google to Remove 57 Firebase Sites Linked to Cyber Scams
 The Indian government has directed Google to take down dozens of websites and databases hosted on Firebase after finding that cybercriminals were allegedly using the platform to impersonate banks, distribute malware, and steal sensitive financial data. According to notices from the Indian Cyber Crime Coordination Centre (I4C), at least 57 Firebase-hosted properties were targeted for removal in August. The case highlights how attackers are increasingly leaning on legitimate cloud services to make scams look more trustworthy.  Investigators said several of the sites were designed to resemble official online services of major Indian banks such as SBI, ICICI Bank, and Axis Bank. Seven of the 57 were reportedly phishing pages built to trick users into entering credentials, while others were used to collect information stolen from victims’ smartphones. The tactics were carefully layered, with fake pages, malicious links, and data collection systems all working together to make the fraud harder to spot.  The I4C also said some campaigns used Android malware disguised as legitimate banking or financial apps. Victims were allegedly lured with offers for new credit cards, reward redemptions, or higher credit limits before being asked to install an app. Once installed, the malware could steal card details, one-time passwords, and other sensitive information, then send it to attacker-controlled infrastructure. Another campaign reportedly abused the PM-KISAN government scheme by promising help with payments and pushing users to download a malicious app.  Security researchers have described similar malware families as “Android God Mode” because they can gain broad access to infected devices and the data stored across multiple apps. In this case, the appeal of Firebase appears to have been its database features and free or low-cost hosting options, which can be abused to create scalable scam operations. That makes legitimate cloud platforms a growing concern for regulators and cybersecurity teams alike.  Google said it has strict policies against phishing, malware, and financial fraud and works with law enforcement agencies, including the I4C, to review abuse reports and remove harmful content. The notices reportedly gave Google just three hours to act, warning of legal action if the flagged links remained live. The episode is another reminder that users should verify banking apps carefully, avoid sideloading unknown APKs, and treat urgent payment or reward messages with caution.
dlvr.it
September 11, 2026 at 5:35 AM
New Android Malware ‘Sturnus’ Bypasses Encrypted Messaging Protections #AndroidTrojan #EncryptedChats #malware
New Android Malware ‘Sturnus’ Bypasses Encrypted Messaging Protections
 Researchers at MTI Security have unearthed a particularly advanced strain of Android malware called Sturnus, which threatens to compromise the data and security of mobile phone owners. The malware reportedly employs advanced interception techniques to capture data and circumvent even the best application-level encryption, making the security features of popular messaging apps like WhatsApp, Telegram and Signal pointless.  The Sturnus malware does not need to crack encryption, according to MTI. Instead, it uses a sophisticated trick: the malware takes a screenshot once the messages have been decrypted for viewing.By exploiting a device’s ability to read the on-screen contents in real time, Sturnus can steal private message texts without leaving a trace. This means that scammers can access sensitive chats, and potentially collect personally identifiable information (PII) or financial data if shared in secure chats.  In addition to message interception, Sturnus employs complex social engineering to steal credentials. The malware is capable to display fake login screens that looks like real banking apps, and can be very convincing. Users can inadvertently provide their information to the hackers if they use their login details on these fake sites.  Sturnus can also simulate an Android system update screen, making the victim believe a normal update is being installed while malicious operations take place in the background. Perhaps most disturbingly, the researchers warn that Sturnus can also increase its privileges by tracking unlock attempts and recording device passwords or PINs. This allows the malware to gain root access which lets the attackers prevent the victims from removing the malicious code or regaining control of their devices.  The majority of Sturnus infections detected so far are positively grouped in Southern and Central Europe, according to surveillance and analysis by the cybersecurity firm Threat Fabric. Such a restricted geography suggests that threat actors are still experimenting with the capabilities of the malware and the way it operates before potentially launching a worldwide campaign.  Experts recommend users of Android to be cautious, refrain from downloading apps from unknown sources and be wary when asked accessibility or overlay permissions to apps they don’t know. But with its progress, Sturnus also exhibits the increasing complexity of Android malware and the difficulty in keeping users safe in a landscape of continuously evolving mobile threats.
dlvr.it
December 4, 2025 at 3:03 PM
BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators #Android #AndroidEcosystem #AndroidTrojan
BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators
 The Android remote access trojan known as BTMOB most likely began as a centralized malware-as-a-service operation but transformed into a wider ecosystem, with resellers, source code buyers, rogue operators, and possibly even impersonators, according to the Flare researchers. BTMOB is a remote access trojan for Android devices that takes the form of malware-as-a-service. It offers an “exploit chain,” that is, a malicious application, droppers, a payload builder, a Windows operator panel, servers, and phishing and credential-stealing tools. All of the components may be purchased in various combinations, depending on the chosen subscription plan. Some of the options include private infrastructure, customized builds, and technical support. The Flare researchers analyzed thousands of relevant forum and chat threads to document BTMOB’s activity and distribution channels.  They tracked the malware’s progress from its first appearances in mid-2025 to the present day. In their findings, the researchers observed that while an official channel was distributing the service and its components, other purportedly independent channels and forums sold subscriptions, reseller panels, code, and even alternative versions of the malware under the same name. In particular, the official account announced the V2 of the malware for rent or sale for $700 per month, $3,000 for a lifetime subscription or $5,000 with additional monthly payments for the private infrastructure and support. Less than a month later, the same account announced technical issues and claimed that over 4,000 devices were connected to BTMOB’s servers.  According to the researchers, the account advertised a full source code and setup instructions for BTMOB for $20,000. The package included PHP and Node.js server components, a VB.NET control panel and Java Android code. The advertised source-code price later fell to $10,000 in May 2025. Additionally, they noticed that the Spanish/Portuguese Telegram channel had an issue between two admins, one of whom left the project. The main channel then announced that from now on, all the administrators would function independently.  It also stated that one of them, based in Brazil, had bought the source code and was running his own fork of BTMOB. After that, the secondary market appeared and started advertising much cheaper alternatives to the official subscription. In particular, one Telegram campaign announced the lifetime access to version 4.1.2 and 4.2 of BTMOB for $500 and purported RAT and server source code for $1,500. Other channels and forums also offered subscriptions, reseller panels, source code, and lifetime accounts for different prices and conditions.   It is unclear whether the accounts offering the alternative versions of BTMOB are legitimate or not, as many of them could have used pirated materials or have been scams. For example, the official account warned all their partners that there is only one official BTMOB channel and that other accounts do not represent the company and are not affiliated with it.  Nevertheless, the official account advertised the V4.1 release in February 2026 and V4.5 in April 2026. According to the announcement, the subscription for the private server hosting of several accounts costs about $1,200 lifetime account, a $3,000, and the source code for the server itself costs $7,000.
dlvr.it
August 21, 2026 at 3:03 PM
MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign #AndroidTrojan #DataTheft #malware
MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign
 MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to both lock users out of their devices and harvest sensitive personal data. Discovered by Zimperium's zLabs team and detailed in a September 9 technical write-up, the threat appears linked to Indonesian actors and spreads primarily via sideloaded APKs hosted on third-party file-sharing platforms. This dual-function design marks a significant escalation in mobile threats, combining financial extortion with deep surveillance to maximize victim impact.  Once installed, MantaxOtax requests device administrator privileges, followed by permissions for SMS, contacts, audio, images, and Android Accessibility services, which grant it deep control over user interactions. It dynamically resolves its command-and-control (C2) domain from a GitHub repository, allowing operators to shift infrastructure without modifying the malware code.  On Android 9 and earlier, it recursively scans external storage, encrypts files using AES with unique per-device keys fetched from C2, deletes originals, and leaves behind .enc files; on Android 10+, Scoped Storage limits encryption to the app's own directory. The malware also overwrites victims' images with ransom notes and opens a Firebase-based chat interface for extortion negotiations, which researchers found partially exposed due to a server misconfiguration.  Beyond encryption, MantaxOtax operates as a full-featured spyware, collecting app inventories, hardware specs, location, browser history, notifications, contacts, call logs, and SMS—including one-time passwords (OTPs). It exfiltrates gallery content, linked Google accounts, WhatsApp profiles and messages (via Accessibility), and Telegram credentials and chat histories. By abusing Android's MediaProjection API, it captures screenshots, records MP4 screen videos, and streams near-real-time footage to attackers, storing media on the Catbox file host. It can also silently activate front or rear cameras to take photos without user knowledge, turning infected devices into always-on surveillance tools.  Researchers observed multiple variants employing psychological pressure tactics: persistent screen locks, application blocking, and transparent overlays that hijack all touch input. Some versions bombard victims with repeating alert dialogs, full-screen video overlays, and image popups appearing every 600 milliseconds, while others use text-to-speech to audibly deliver attacker messages. A second iteration adopted WebSocket communications for more resilient C2 channels and added features like continuous screen locking and app blacklisting, making remediation harder for average users. These harassment techniques are designed to overwhelm victims into compliance, increasing the likelihood of ransom payment or credential surrender.  Evidence including language markers and recovered victim files suggests MantaxOtax primarily targets Indonesian users. The misconfigured server also leaked what appears to be the operators' control panel, offering rare insight into their infrastructure. This campaign follows closely after the discovery of THost9, another Android trojan that clones banking apps into isolated work profiles to evade detection. Together, these threats underscore a growing trend of multi-stage mobile malware combining financial fraud, surveillance, and ransomware—highlighting the critical need for users to avoid sideloading apps, keep devices updated with the latest security patches, and use reputable mobile security solutions to detect and block such sophisticated threats before they cause harm.
dlvr.it
September 12, 2026 at 3:10 PM
Millions of Devices at Risk: New Trojan Monitors Smartphones #AndroidTrojan #DataHarvesting #DataLeak
Millions of Devices at Risk: New Trojan Monitors Smartphones
 A menacing new Trojan has emerged that puts millions of smartphone devices worldwide at risk, according to recent cybersecurity reports. This sophisticated malware specifically targets Android devices and has already infected thousands of users across 143 countries. The Trojan's ability to monitor smartphones in real-time represents a significant evolution in mobile cyberthreats, with security researchers warning that the actual infection count could be far higher than currently detected. The malware spreads primarily through seemingly legitimate websites that trick users into downloading malicious applications. Once installed, the Trojan grants hackers complete remote control over compromised devices, enabling live monitoring of user activities. Security firm Zimperium zLabs identified similar dangerous Trojans like Arsink, which impersonates popular brands including WhatsApp and TikTok to evade detection. The infected devices can have their audio recorded, text messages read, and even be wiped completely by attackers.  This Trojan's most alarming capability is its live monitoring feature combined with coordinated attack systems. Beyond stealing credentials, the malware transmits live screen content to remote servers, creating a continuous visual feed that allows attackers to observe activity and intercept authentication steps in real time. Encrypted communication channels connect infected devices to centralized command systems that coordinate attacks and distribute updated instructions, managing thousands of compromised devices simultaneously. The infection has created a massive footprint, with Egypt reporting around 13,000 compromised phones, Indonesia approximately 7,000, and Iraq and Yemen each with 3,000 infections.  The Trojan harvests an extensive range of sensitive data including SMS messages, call logs, contacts, device location, and Google account information. It can steal user accounts in messengers and social networks, stealthily send messages on behalf of victims, monitor browser activities, replace links, swap numbers during calls, and intercept SMS messages. Previous similar malware campaigns have already stolen at least $270,000 worth of cryptocurrency, suggesting the financial damage from this new Trojan could be substantial.  Experts recommend several critical protection measures to safeguard against this threat. Users should only download applications from official app stores like Google Play, avoid clicking links from suspicious websites, and keep their Android operating system updated with the latest security patches. Google has warned that over 40% of Android devices remain vulnerable because they run outdated versions without security support. If your smartphone brand no longer provides security updates, experts strongly recommend considering a new device to protect your personal data.
dlvr.it
May 23, 2026 at 4:12 PM
Android Users Face New WhatsApp Malware Threat #Albiriox #AndroidTrojan #malware
Android Users Face New WhatsApp Malware Threat
 Cybersecurity researchers at security firm Cleafy have issued a warning regarding a high risk malware campaign aimed at Android users via WhatsApp messages that could jeopardize users' cryptocurrency wallets and bank information. The researchers tracked the threat as Albiriox, a new emerging Android malware family being marketed as malware-as-a-service (MaaS) on underground cybercrime forums.  Modus operandi  The malware propagate through WhatsApp messages which include links to malicious websites that impersonate Google Play Store pages. Currently, they are impersonating a popular discount retail app, but this could quickly change both in terms of campaigns and targets. Rather than having the app delivered directly, victims are persuaded to submit their phone number, on the premise that an installation link will be sent to them on WhatsApp.  After users tap on and download the trojanised app, Albiriox is able to take full control of the compromised device. The malware overlays attacks on more than 400 cryptocurrency wallet and banking apps — displaying fake login screens on top of the legitimate apps to capture credentials as users input them.  Albiriox is an advanced, rapidly evolving malware. The malware also features Vnc-based remote access, which gives the attackers the ability to directly control the infected machines. Initially, campaigns were targeted at Austrian citizens with German-language messages, but is now broadening its reach. The malware is obfuscated with JSONPacker and also it tricks users into allowing the "Install Unknown Apps" permission. When it is running, it contacts its command servers through unencrypted TCP and stays on the bot forever, maintaining active control through a regular series of ping-pong heartbeat messages.  Mitigation tips Security experts emphasize that users should never agree to install apps through phone number submission on websites. Any WhatsApp messages requesting app installations should be immediately deleted without clicking links. This distribution method represents exactly why Google is strengthening measures against sideloading, requiring app developers to register and verify their identities. Cleafy highlights that Albiriox demonstrates the ongoing evolution and increasing sophistication of mobile banking threats. However, users can protect themselves effectively by following several key practices: only install apps from the official Google Play Store, ensure Play Protect is activated, and remain skeptical of any unsolicited installation requests received through messaging apps.  The campaign highlights broader security concerns affecting WhatsApp and similar platforms, particularly as attackers combine social engineering with technical malware capabilities to compromise both devices and accounts.
dlvr.it
December 7, 2025 at 1:15 PM
PixRevolution is an Android trojan that hijacks Brazil’s PIX payments by streaming victims’ screens in real time and replacing transfer recipients via operator control using Accessibility and MediaProjection APIs. #PIXFraud #AndroidTrojan #Brazil
PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time
PixRevolution is a novel Android banking trojan that streams victims' screens in real time and uses an operator (human or AI) to replace PIX recipients during a transfer, redirecting funds instantly. It is distributed via convincing fake Google Play Store pages and impersonated Brazilian brands, exploiting Accessibility and MediaProjection APIs to operate stealthily and evade signature-based detection. #PixRevolution #PIX
www.hendryadrian.com
March 12, 2026 at 11:00 AM
📣 New Podcast! "Anatsa Unleashed | Android Banking Trojan Targets Over 830 Financial Apps Globally" on @Spreaker #anatsa #androidmalware #androidtrojan #bankingtrojan #cryptosecurity #googleplay #mobilebanking #securityweek #threatlabz #zscaler
Anatsa Unleashed | Android Banking Trojan Targets Over 830 Financial Apps Globally
Episode Title: Anatsa Unleashed: How a Sophisticated Android Banking Trojan Targets Over 830 Financial Apps Globally In this episode of "Upwardly Mobile," we dive deep into the alarming evolution of Anatsa, a potent Android banking trojan that has significantly expanded its reach, now setting its sights on over 830 financial applications worldwide . First identified in 2020, Anatsa (also known as Teabot or Troddler) grants its operators full control over infected devices, enabling them to perform fraudulent transactions and steal critical bank information, cryptocurrencies, and various other data on behalf of victims. What You'll Learn in This Episode: • Anatsa's Expanded Targets: Discover how the Anatsa banking trojan has broadened its scope to include more than 150 new banking and cryptocurrency applications, extending its malicious campaigns to mobile users in new countries like Germany and South Korea . • Deceptive Distribution Methods: Understand the cunning ways Anatsa spreads, primarily through decoy applications found on the official Google Play Store . These seemingly harmless apps often masquerade as useful tools like PDF viewers, QR code scanners, or phone cleaners, accumulating over 50,000 downloads in some cases. Once installed, they silently fetch a malicious payload disguised as an update from Anatsa's command-and-control (C&C) server. • Advanced Evasion Techniques: Learn about Anatsa's sophisticated anti-analysis and anti-detection mechanisms, designed to evade security measures. These include decrypting strings at runtime using dynamically generated Data Encryption Standard (DES) keys, performing emulation and device model checks, and periodically altering package names and installation hashes . The malware even hides its DEX payload within corrupted archives that bypass standard static analysis tools. • How Anatsa Compromises Devices: Find out how Anatsa requests and automatically enables critical accessibility permissions upon installation. This allows it to display overlays on top of legitimate applications, tamper with notifications, receive and read SMS messages, and ultimately present fake banking login pages to steal credentials . The trojan also incorporates keylogging capabilities. • Industry Response: Hear about the efforts of cybersecurity firms like Zscaler, which identified and reported 77 nefarious applications distributing Anatsa and other malware families, collectively accounting for over 19 million downloads . While Google has since removed these reported applications and states that Google Play Protect offers automatic protection, the continuous evolution of Anatsa highlights the ongoing threat. Protect Yourself: Cybersecurity experts advise Android users to always verify the permissions that applications request and ensure they align with the intended functionality of the app . -------------------------------------------------------------------------------- Relevant Links to Source Materials: • Source 1: SecurityWeek Article on Anatsa: https://www.google.com/url?sa=E&q=https%3A%2F%2Fsecurityweek.com%2Fanatsa-android-banking-trojan-now-targeting-830-financial-apps%2F • Source 2: Zscaler ThreatLabz Report: https://www.google.com/url?sa=E&q=https%3A%2F%2Fwww.zscaler.com%2Fblogs%2Fsecurity-research%2Fanatsas-latest-updates-android-document-readers-and-deception • Source 3: BSI Report on Anatsa: https://www.google.com/url?sa=E&q=https%3A%2F%2Fwww.bsi.bund.de%2FEN%2FTheBSI%2FCybernationGermany%2FITsecurityIncident%2FAnatsa_Teabot%2Fanatsa_teabot_node.html -------------------------------------------------------------------------------- Sponsor: This episode of "Upwardly Mobile" is brought to you by https://approov.io. Learn more about securing your mobile applications at approov.io. -------------------------------------------------------------------------------- Keywords: Anatsa, Android banking trojan, mobile security, cybersecurity, financial apps, Google Play, malware, credential theft, keylogging, fraudulent transactions, Zscaler, threat intelligence, Android malware, cryptocurrency, mobile banking, data protection, Teabot, Troddler, anti-analysis, C&C server.
www.spreaker.com
August 28, 2025 at 6:25 PM
PlayPraetor Android Trojan Infects 11000+ Devices via Fake Google Play Pages and Meta Ads reconbee.com/playpraetor-...

#PlayPraetor #androidtrojan #googleplay #MetaAds #Google #cyberattack
PlayPraetor Android Trojan Infects 11000+ Devices via Fake Google Play Pages and Meta Ads
carry out a coordinated read more about PlayPraetor Android Trojan Infects 11000+ Devices via Fake Google Play Pages and Meta Ads
reconbee.com
August 4, 2025 at 8:06 AM
~Infoblox~
A global Android banking trojan MaaS operated from Cambodian scam centers uses forced labor to steal credentials and biometrics.
-
IOCs: 103. 214. 169. 197, 18. 167. 169. 60, 38. 47. 52. 4
-
#AndroidTrojan #MaaS #ThreatIntel
Cambodian Scam Center Android MaaS
www.infoblox.com
April 9, 2026 at 12:34 PM