#PlayPraetor
-SonicWall hacking spree deploys Akira
-Profile of ShadowSyndicate ransomware affiliate
-Ransomware gangs go to physical threats
-New malicious Firefox extensions
-New Plague Linux backdoor
-PlayPraetor RAT infects 11k
-Qilin may have exit-scammed
-Volt Boot attack
-New Adobe CISO
-DEFCON bans a 5th
August 4, 2025 at 6:38 AM
More than 11,000 Android devices have been infected with a new Android RAT named PlayPraetor.

The malware launched this year by Chinese-speaking developers, and is available to rent via a Malware-as-a-Service model.

www.cleafy.com/cleafy-labs/...
PlayPraetor's evolving threat: How Chinese-speaking actors globally scale an Android RAT | Cleafy
The Cleafy Threat Intelligence Team has uncovered a large-scale Malware-as-a-Service (MaaS) operation orchestrated by Chinese-speaking Threat Actors. The operation has globally infected over 11,000 An...
www.cleafy.com
August 3, 2025 at 10:51 AM
Related threats include ToxicPanda (3,000 infections via fake Chrome updates) and DoubleTrouble, spread through Discord.

Full article:
https://thehackernews.com/2025/08/playpraetor-android-trojan-infects.html
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads
thehackernews.com
August 5, 2025 at 5:19 AM
🚨Cyber Alert‼️

🇪🇸🇵🇹🇫🇷🇲🇦🇵🇪🇭🇰
PlayPraetor, a new Android RAT, has infected over 11,000 devices, mainly in Portugal, Spain, France, Morocco, Peru, and Hong Kong, growing by 2,000 weekly. It's spread via fake Google Play pages pushed through Meta Ads and SMS phishing.
August 5, 2025 at 5:19 AM
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
August 4, 2025 at 11:58 AM
📌 Malware "瘟疫" hits Linux servers, bypassing 66 antivirus engines. Android Trojan PlayPraetor infects 1.1M devices. #CyberSecurity #Malware https://tinyurl.com/2ylb2kwg
Emerging Threats: Linux Malware Evades Detection, Android Trojan Infects Millions
A recent report highlights two emerging malware threats with limited technical details disclosed. The first is a malware named "瘟疫" targeting Linux servers, reportedly capable of evading detection by 66 antivirus engines. The second is an Android Trojan called PlayPraetor, which has infected over 1.1 million devices. However, the original article does not provide technical specifics or real-world impacts of these attacks. For cybersecurity professionals, while the available information is sparse, these reports underscore the continuous evolution of malware threats across different platforms. The reported evasion capabilities of the Linux malware and the scale of the Android Trojan infections emphasize the necessity for robust, multi-layered security defenses. In the absence of detailed threat intelligence, organizations should prioritize advanced detection methods, proactive monitoring, and comprehensive security strategies to mitigate potential risks. The lack of specific technical information in the source material limits a more detailed analysis. However, the reported scale and evasion capabilities of these threats serve as a stark reminder of the dynamic and challenging nature of contemporary cybersecurity threats.
tinyurl.com
August 5, 2025 at 5:42 PM
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads

Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru,…
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads
Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru, and Hong Kong. "The botnet's rapid growth, which now exceeds 2,000 new infections per week, is driven by aggressive campaigns focusing on Spanish and French speakers, indicating a strategic shift away from its previous common victim base," Cleafy researchers Simone Mattia, Alessandro Strino, and Federico Valentini said in an analysis of the malware.
nexttech-news.com
August 4, 2025 at 10:17 AM
揭秘PlayPraetor安卓木马:通过假冒谷歌商店页面和Meta广告感染逾1.1万台设备

https://qian.cx/posts/E3F8B15D-6C71-41BF-9465-4DC7B8E6EB4B
December 4, 2025 at 12:57 PM
CTM360揭露大规模假冒Play Store诈骗:PlayPraetor木马的威胁

https://qian.cx/posts/C5ED3321-EDA2-4D99-916B-0212C8D74231
April 3, 2025 at 9:24 AM
Considerado ameaça global, trojan PlayPraetor já infectou mais de 11 mil dispositivos Android
Um novo malware de acesso remoto foi descoberto em circulação e já comprometeu mais de 11 mil dispositivos. Chamado de PlayPraetor, o trojan possui estrutura semelhante a outras ferramentas da categoria e tem como objetivo obter controle remoto do dispositivo e roubar credenciais de apps bancários e carteiras digitais. O **PlayPraetor é um Android RAT (Remote Access Trojan) distribuído por meio de links maliciosos enviados via SMS ou por anúncios hospedados no Meta Ads**. O controle do malware é feito por um painel command-and-control (C2) de origem chinesa. * **Leia mais:****Mailchimp sofre vazamento de dados após invasão do grupo de ransomware** "O crescimento da rede de bots, que agora excede a marca de 2 mil infecções por semana, é impulsionado por uma campanha agressiva focada em usuários que falam espanhol e francês, indicando uma mudança de estratégia em relação à base de vítimas anterior", explicaram pesquisadores da empresa de cibersegurança Cleafy. Nova campanha de malware se manifesta em diferentes variantes. (Fonte: Security Affairs, Cleafy) ## Como funciona o malware PlayPraetor? O **PlayPraetor foi identificado pela primeira vez pela empresa CTM360, em março de 2025**. Segundo os pesquisadores, ele era distribuído por meio de milhares de páginas fraudulentas que imitavam a Play Store. "Os links se passam por páginas da Play Store, distribuídos por meio do Meta Ads e mensagens SMS, com o objetivo de alcançar um público amplo. Esses anúncios e mensagens maliciosas convencem o usuário a clicar nos links, direcionando-os a páginas falsas com APKs infectados", detalhou a empresa. Assim como outros malwares, **os criminosos tentam convencer o usuário de que o aplicativo é legítimo**. ### Quais são as cinco variações da campanha de disseminação do PlayPraetor? * Progressive Web App (PWA): web app falso que cria atalhos e envia notificações para atrair interações; * Apps WebView (Phish): app que abre uma página falsa de phishing para roubo de credenciais; * PlayPraetor (Phantom): permite execução persistente de código remoto; * PlayPraetor RAT: trojan completo de acesso remoto; * PlayPraetor Veil: se disfarça como uma marca legítima para aplicar golpes de phishing. ## Quais são os alvos do PlayPraetor? O PlayPraetor mira tanto usuários domésticos quanto corporativos, oferecendo vantagens para os criminosos independentemente do perfil da vítima. Atualmente, **58% dos casos registrados estão concentrados em Portugal, Espanha e França. Marrocos, Peru e Hong Kong também aparecem entre os países mais afetados**. Após sua identificação no sul da Europa e na América Latina, o **PlayPraetor foi considerado uma ameaça cibernética global**. Este malware é mais um exemplo de campanha operada por grupos falantes de chinês voltada à prática de fraudes bancárias. **Outros casos semelhantes incluem o ToxicPanda e o SuperCard X** , ambos identificados em 2024. Quer se proteger contra os malwares mais recentes e manter seus dados seguros? Siga o **TecMundo** nas redes sociais e acompanhe as principais atualizações sobre cibersegurança e tecnologia.
www.tecmundo.com.br
August 4, 2025 at 7:05 PM
Виртуальные угрозы: Как CTM360 раскрыла крупную аферу с поддельным Play Store и Trojan PlayPraetor

https://kripta.biz/posts/B309E84C-7D41-4ECB-B8D7-9C1C1164A05C
April 3, 2025 at 9:23 AM
PlayPraetor Android RAT expands rapidly across Spanish and French-speaking regions
PlayPraetor Android RAT expands rapidly across Spanish and French-speaking regions
PlayPraetor Android RAT has hit 11K+ devices, spreading fast via campaigns targeting Spanish and French speakers, say Cleafy researchers.
securityaffairs.com
August 4, 2025 at 1:38 PM
PlayPraetor Android trojan infects >11k devices through sophisticated fraud campaign.

A newly discovered Android remote access trojan (RAT) known as PlayPraetor has rapidly surged across the globe, infecting more than 11,000 devices in countries including Portugal, Spain, France, Morocco, Peru,…
PlayPraetor Android trojan infects >11k devices through sophisticated fraud campaign.
A newly discovered Android remote access trojan (RAT) known as PlayPraetor has rapidly surged across the globe, infecting more than 11,000 devices in countries including Portugal, Spain, France, Morocco, Peru, and Hong Kong. Security researchers have warned that the malware’s reach is expanding at a rate of over 2,000 new infections weekly, driven primarily by aggressive campaigns targeting Spanish- and French-speaking users.
www.spartechsoftware.com
August 4, 2025 at 12:55 PM
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads

Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru,…
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads
Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru, and Hong Kong. "The botnet's rapid growth, which now exceeds 2,000 new infections per week, is driven by aggressive campaigns focusing on Spanish and French speakers, indicating a strategic shift away from its previous common victim base," Cleafy researchers Simone Mattia, Alessandro Strino, and Federico Valentini said in an analysis of the malware.
nexttech-news.com
August 4, 2025 at 10:16 AM
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data

www.tomsguide.com/computing/ma...
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Over 6,000 malicious sites are spreading the PlayPraetor Trojan
www.tomsguide.com
March 11, 2025 at 12:38 PM
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads
Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru...
Link Preview
Visit the link for more information
thehackernews.com
August 4, 2025 at 7:25 AM
#Cybersécurité: #PlayPraetor, un malware qui cible les données bancaires et cryptos

Capable de prendre le contrôle total d’un téléphone et de voler des données bancaires, il marque une nouvelle évolution du cybercrime mobile
fr.le360.ma/economie/cyb...
Cybersécurité: PlayPraetor, un malware qui cible les données bancaires et cryptos
Un nouveau malware baptisé PlayPraetor cible massivement les smartphones Android, avec une propagation fulgurante qui touche déjà le Royaume et plusieurs pays francophones. Capable de prendre le contr...
fr.le360.ma
August 12, 2025 at 5:40 AM
PlayPraetor Android RAT Operation Grows Globally with MaaS Expansion
PlayPraetor Android RAT Operation Grows Globally with MaaS Expansion
A large-scale Malware-as-a-Service (MaaS) campaign operated by Chinese-speaking threat actors has deployed the PlayPraetor Android Remote Access Trojan (RAT) on over 11,000 devices worldwide, using so...
cyberinsider.com
August 2, 2025 at 7:29 AM
🚨 Ciberalerta: PlayPraetor ya ha infectado más de 11 000 dispositivos Android en todo el mundo. Una amenaza que crece sin pausa.
En este video te contamos todo lo que tienes que saber de esta nueva amenaza para los usuarios Android.
#Ciberseguridad #Seguridad #Android #Malware #Troyanos #Virus
August 8, 2025 at 11:32 PM
PlayPraetor Android RAT expands rapidly across Spanish and French-speaking regions

PlayPraetor Android RAT has hit 11K+ devices, spreading fast via campaigns targeting Spanish and French speakers, say Cleafy researchers. Cleafy researchers have identified a new Android RAT calle…

#hackernews #news
PlayPraetor Android RAT expands rapidly across Spanish and French-speaking regions
PlayPraetor Android RAT has hit 11K+ devices, spreading fast via campaigns targeting Spanish and French speakers, say Cleafy researchers. Cleafy researchers have identified a new Android RAT called PlayPraetor, which has infected over 11,000 devices, mainly in Portugal, Spain, France, Morocco, Peru, and Hong Kong. The malware is spreading rapidly, with more than 2,000 new […]
securityaffairs.com
August 5, 2025 at 6:05 AM
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads

Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain…

#hackernews #meta #news
PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads
Cybersecurity researchers have discovered a nascent Android remote access trojan (RAT) called PlayPraetor that has infected more than 11,000 devices, primarily across Portugal, Spain, France, Morocco, Peru, and Hong Kong. "The botnet's rapid growth, which now exceeds 2,000 new infections per week, is driven by aggressive campaigns focusing on Spanish and French speakers, indicating a strategic
thehackernews.com
August 5, 2025 at 2:17 AM
PlayPraetor Reloaded: CTM360 Uncovers a Play Masquerading Party

Overview of the PlayPraetor Masquerading Party Variants
CTM360 has now identified a much larger extent of the ongoing Play Praetor campaign. What started with 6000+ URLs of a very specific banking attack has now gro…

#hackernews #news
PlayPraetor Reloaded: CTM360 Uncovers a Play Masquerading Party
Overview of the PlayPraetor Masquerading Party Variants CTM360 has now identified a much larger extent of the ongoing Play Praetor campaign. What started with 6000+ URLs of a very specific banking attack has now grown to 16,000+ with multiple variants. This research is ongoing, and much more is expected to be discovered in the coming days.  As before, all the newly discovered play
thehackernews.com
April 11, 2025 at 9:22 AM
New Android Malware ‘PlayPraetor’ Hits 11,000 Devices — A Sophisticated Global Threat Emerges

Introduction: The Rise of a New Mobile Menace A dangerous new Android malware named PlayPraetor has been uncovered by cybersecurity firm Cleafy. With over 11,000 confirmed infections and counting, this…
New Android Malware ‘PlayPraetor’ Hits 11,000 Devices — A Sophisticated Global Threat Emerges
Introduction: The Rise of a New Mobile Menace A dangerous new Android malware named PlayPraetor has been uncovered by cybersecurity firm Cleafy. With over 11,000 confirmed infections and counting, this Remote Access Trojan (RAT) has quickly escalated into a major international threat, targeting users mainly in Portugal, Spain, France, Morocco, Peru, and Hong Kong. Unlike many prior malware campaigns that used brute-force techniques or crude phishing, PlayPraetor introduces a multi-layered, professionally executed strategy — leveraging fake Google Play Store pages, modular attack variants, and a Chinese-language command-and-control (C2) infrastructure to dominate victims' mobile devices.
undercodenews.com
August 4, 2025 at 7:29 PM
Inside the Rise of PlayPraetor: The Ruthless Android Malware Hijacking Devices Worldwide

A Dangerous New Threat in the Android World Cybersecurity experts have sounded the alarm over a stealthy new Android malware dubbed PlayPraetor, which has infected over 11,000 devices globally. Originating…
Inside the Rise of PlayPraetor: The Ruthless Android Malware Hijacking Devices Worldwide
A Dangerous New Threat in the Android World Cybersecurity experts have sounded the alarm over a stealthy new Android malware dubbed PlayPraetor, which has infected over 11,000 devices globally. Originating from Chinese-speaking threat actors, this sophisticated Remote Access Trojan (RAT) is designed to hijack mobile banking sessions, steal personal data, and maintain deep control over compromised devices. Its spread has been explosive — more than 2,000 new devices are infected each week, with a growing focus on Spanish and French speakers.
undercodenews.com
August 4, 2025 at 6:45 AM