Sign in

David Blanc

@speekha.bsky.social
84 followers 122 following 168 posts

Mobile Security Expert at BPCE-SI. Former #Android lead developer. Definite Kotlin lover. Author of HttpMocker. Technical speaker.

PostsRepliesMedia
Reposted by David Blanc
Devfest Toulouse @devfesttoulouse.fr · 15h
🎤 Le programme du #DevFestToulouse 2026 est COMPLET ! Toutes les conférences sont en ligne : explorez, filtrez, ajoutez vos favorites et construisez votre journée du 19 novembre 👀 🎟️ Il ne manque plus que votre billet !
211
Reposted by David Blanc
InfoSec @infosec.skyfleet.blue · 14h
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
thehackernews.com
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Public PoC for CVE-2026-86950 triggers a controlled out-of-bounds write in CoreGraphics; code execution is not demonstrated.
011
David Blanc @speekha.bsky.social · 30/09/2026
This is what cybersec nightmares are made of.
010
David Blanc @speekha.bsky.social · 30/09/2026
As I prepare for my talks in the next few weeks, that was a super handy reminder of some good principles to keep in mind when preparing your slide deck. We'll see how good I am at following them!
000
Reposted by David Blanc
InfoSec @infosec.skyfleet.blue · 30/09/2026
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
cybersecuritynews.com
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots. Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia. Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three generations of the malware’s operator panel between April and September 2026. Samples from late 2025, February 2026 and current campaigns retained a similar design, while the infrastructure behind them changed substantially. Earlier campaigns used cryptocurrency trading and adult entertainment decoys. Cleafy said in a report shared with Cyber Security News (CSN) that nearly 100 separate deployments had appeared since April 2026. RATHat Architecture (Source – Cleafy) Licensing restrictions and parallel campaigns support a malware-as-a-service model, rather than proving one central group controls every deployment. RATHat Android Malware After receiving Accessibility access, RATHat navigates the phone’s settings, enables wireless debugging and reads the pairing code displayed on screen. It pairs with the local Android Debug Bridge service, gaining access as the shell user, identified by Android as UID 2000. The pairing process relies on finding specific controls, but fixed instructions can fail on unfamiliar manufacturer interfaces, Android versions or languages. When that happens, the malware sends Gemini a structured description of the live interface and asks where to tap. Gemini returns coordinates or short text that helps resolve an unfamiliar label. Requests go directly from the phone to Gemini Flash models using a key stored in the malware configuration, rather than passing through the attackers’ command server. This resembles the adaptive navigation seen in Gemini assisted Android spyware that replaces rigid screen instructions with model responses. The C2 Panels Observed (Source – Cleafy) In RATHat, however, the observed device-side AI function specifically keeps the wireless-debugging pairing sequence working when ordinary text matching fails. Once pairing succeeds, an operator can deploy a separate service written in Go with one click. It runs independently of the app, opens a local HTTP server on port 7912 and remains reachable through a reverse tunnel to the attacker’s infrastructure. The service can capture screen content and inject touches using Android testing tools without the usual screen-recording prompt or indicator. Cleafy noted that those tools do not work on Android 14 and later, leaving newer devices dependent on app-based capture with user consent. Fraud Infrastructure The command panel evolved from BlackCat into Panda Workshop V5 and V6. V5 introduced operator two-factor authentication and an AI balance-scoring widget, while V6 obscured its frontend code, added phishing download-page templates and consolidated AI settings around Gemini. Operators can build, package, sign and publish malicious apps without leaving the console. Scheduled rebuilding produces fresh files while keeping the underlying implant unchanged, helping campaigns evade detection methods that depend on recognizing previously recorded file hashes. Alongside remote control, the panel exposes stolen messages, credentials, contacts, photographs and files. Fake screens placed over targeted apps capture entered information. Similar ToxicPanda wireless debugging abuse shows why this developer feature has become a concern beyond conventional credential theft. A separate AI function analyzes collected SMS messages to estimate victims’ bank balances and rank devices by value. It helps operators select targets, rather than carrying out fraud itself. Cleafy found no analyzed sample that used AI-guided navigation to complete a fraudulent transfer. Cleafy recommends monitoring activity executed as UID 2000, extending security checks beyond the application’s permissions and lifecycle. Downloaded testing tools retain recognizable filenames in the temporary deployment directory, providing artifacts that investigators can examine during a suspected compromise. The removal gap is important: deleting the visible app does not immediately stop the independent service, which survives until reboot. The research also warns that AI-assisted interface navigation could reduce the custom engineering needed for future automated banking attacks, although that broader capability was not demonstrated here. Indicators of compromise (IoCs):- Type Indicator Description Domain admin.chunhuating[.]best September 2026 command-and-control infrastructure, Panda Workshop V6. Domain admin.xiongmaocs[.]pics August 2026 command-and-control infrastructure, Panda Workshop V5. IPv4 8.231.120[.]246 April 2026 command-and-control infrastructure, BlackCat. Domain admin.rathat[.]live December 2025 and February 2026 command-and-control infrastructure, Fisher. URL https://dramaspoolcoa[.]com/en.html September 2026 delivery page. MD5 116346cace7f00ba557034b534d40791 September 2026 malware sample. URL https://rathat[.]me/app-release-rat-hat-live.apk December 2025 and February 2026 delivery URL. MD5 8fdc21e25097a46528211274e54330e1 February 2026 malware sample. MD5 f83357b2d47c7d38ee53943373961211 December 2025 malware sample. File name app-release-rat-hat-live.apk Android package filename appearing in the source’s delivery URL. File path /data/local/tmp Deployment directory for the native service and downloaded tools; not inherently malicious. File name minicap Legitimate Android testing tool abused for screen capture; not a unique malware indicator. File name minitouch Legitimate Android testing tool abused to inject touch events; not a unique malware indicator. File name screencap Android screen-capture utility used as a fallback; not a unique malware indicator. URI path /api/bin/arm64-v8a/minicap Example command-server path used to retrieve an architecture-specific screen-capture tool. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC The post RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions appeared first on Cyber Security News .
012
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 29/09/2026
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
bleepingcomputer.com
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
083
Reposted by David Blanc
Help Net Security @helpnetsecurity.com · 29/09/2026
GitHub’s AI agent found 24 Android app vulnerabilities 📖 Read more: www.helpnetsecurity.com/2026/09/29/g... #cybersecurity #cybersecuritynews #AndroidSecurity #AI #InfoSec @github.com
helpnetsecurity.com
GitHub's AI agent found 24 Android app vulnerabilities - Help Net Security
GitHub's AI Android app vulnerabilities research uncovered 24 bugs, including a location leak and a Wikipedia takeover flaw.
021
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 29/09/2026
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
bleepingcomputer.com
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
064
David Blanc @speekha.bsky.social · 28/09/2026
Reminder: that's next week, at @nextapp.bsky.social Berlin! I'll be speaking at 12:00 on Thursday. #nextapp26
ANOM: The Android that took down 1,000 criminals
011
Reposted by David Blanc
Ed Holloway-George 🍝 @spght.dev · 25/09/2026
🚨🎉 There's a new security skill in town! 🎉🚨 Released earlier today, the android-permission-security skill can be used to audit and apply best practices surrounding permission handling You can check it out here or install via the Android CLI: github.com/android/skil...
github.com
skills/security/android-permissions-security at main · android/skills
Contribute to android/skills development by creating an account on GitHub.
031
Reposted by David Blanc
Hackread.com @hackread.bsky.social · 25/09/2026
⚠️📡📶🌐 Your phone could connect to a rogue 5G cell without a tap or warning. Researchers tested 5G-Shark on real devices, collecting identifiers and disrupting service without jamming mobile networks. Listen/Read: hackread.com/5g-shark-pho... #5G #MobileSecurity #Cybersecurity #Privacy
hackread.com
5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
Researchers developed 5G-Shark to lure phones onto rogue base stations, collect subscriber IDs, force network downgrades and trigger service disruptions.
023
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 23/09/2026
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
bleepingcomputer.com
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
004
Reposted by David Blanc
Catalin Cimpanu @campuscodi.risky.biz · 24/09/2026
New RemControl Android banking trojan spotted in the wild RemControl devs tricked an AI coding assistant that it was creating a parental monitoring application but used the code for the trojan's backend servers www.group-ib.com/blog/remcont...
group-ib.com
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
073
Reposted by David Blanc
Hackread.com @hackread.bsky.social · 22/09/2026
RatHat is not your typical Android banking malware. It uses generative #AI to navigate infected devices in real time, steal banking credentials, and intercept OTP codes, and can even reinstall itself after removal. Listen/Read: hackread.com/rathat-andro... #Cybersecurity #Android #Malware #RatHat
hackread.com
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again.
021
Reposted by David Blanc
Anthony Moser @anthonymoser.com · 21/09/2026
8. often, when people say LLMs "can do" something they mean LLMs can produce output that looks like the output of doing something 9. producing something that looks like the output of doing something is not the same thing as doing it
4447111
Reposted by David Blanc
John O'Reilly @johnoreilly.dev · 19/09/2026
TIL you can get IntelliJ to sync project with later AGP version than it officially supports (e.g. one that Android Studio supports and is sometimes required for latest Compose etc) by setting following in idea.properties gradle.ide.support.future.agp.versions=true
idea.properties
1103
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 17/09/2026
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
bleepingcomputer.com
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
027
David Blanc @speekha.bsky.social · 17/09/2026
And then there were three! I just got notice that my talk was also accepted to @droidcon.bsky.social London in December!
Your session was accepted.
020
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 16/09/2026
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
bleepingcomputer.com
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
194
Reposted by David Blanc
Help Net Security @helpnetsecurity.com · 11/09/2026
Getting a stranger’s phone kicked off the cellular network costs a few dollars 📖 Read more: www.helpnetsecurity.com/2026/09/11/c... #cybersecurity #cybersecuritynews #infosec #IoTsecurity #mobilesecurity #5G
helpnetsecurity.com
Getting a stranger's phone kicked off the cellular network costs a few dollars - Help Net Security
Six flaws in lost phone reporting let an attacker block a stranger's phone or home alarm for about $4, researchers found.
001
Reposted by David Blanc
Malwarebytes @malwarebytes.com · 11/09/2026
Researchers found that the Android banking Trojan Gigabud can create a separate work profile and install a cloned banking app inside it. This allows attackers to make fraudulent transactions while potentially hiding their activity from malware detection on the main profile.
bit.ly
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
033
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 11/09/2026
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
bleepingcomputer.com
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
154
Reposted by David Blanc
Jaewoong Eum (skydoves) @skydoves.bsky.social · 13/09/2026
Hot Reload on iOS is no longer a dream. Compose HotSwan v2 introduces Kotlin Multiplatform support, enabling seamless hot reloading across iOS, Android, and Desktop. hotswan.dev/blog/compose...
071
Reposted by David Blanc
Chris Banes @chrisbanes.me · 13/09/2026
Compose now has progressive blur. Do you still need Haze? chrisbanes.me/posts/compos...
chrisbanes.me
Compose has progressive blur. Do you still need Haze?
Compose’s new progressive blur API blurs a composable’s own content. Here’s how that relates to Haze and Android’s new backdrop API.
0113
David Blanc @speekha.bsky.social · 14/09/2026
So ChatGPT supposedly solved the Navier-Stokes equation, but nobody at OpenAI is able to explain it, because none of their researchers have the expertise with Navier-Stokes to properly understand what the LLM produced... 🤦
010
Reposted by David Blanc
Hackread.com @hackread.bsky.social · 14/09/2026
Thousands of suspicious Android apps found abusing Google Play Early Access to push fake rewards, deepfake promotions, misleading utilities, and fraudulent ad clicks. Listen/Read: hackread.com/google-play-... #Cybersecurity #Android #GooglePlay #Scams #Deepfake
hackread.com
Google Play Early Access Abused by Thousands of Suspicious Android Apps
Bitdefender finds thousands of suspicious Android apps abusing Google Play Early Access with fake rewards, deepfake ads, misleading utilities and brand impersonation.
032
David Blanc @speekha.bsky.social · 11/09/2026
I just passed the GIAC Mobile Device Security Analyst Certification! #CyberSecurity #MobileSecurity #Pentesting
GIAC Mobile Device Security Analyst Badge
000
Reposted by David Blanc
Catalin Cimpanu @campuscodi.risky.biz · 08/09/2026
Calif developed a zero-click worm that spread through WeChat calls across iOS and Android blog.calif.io/p/weworm
blog.calif.io
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
051
David Blanc @speekha.bsky.social · 10/09/2026
😳
000
Reposted by David Blanc
Kotlin by JetBrains @kotlinlang.org · 10/09/2026
📸 Adding image selection or camera capture to your KMP app? ImagePickerKMP provides a single API for camera and gallery flows across Android, iOS, desktop, web, and Wasm – with cropping, compression, permission handling, and a customizable UI. See what it can do on Klibs.io 👇 kotl.in/b2tunt
021
Reposted by David Blanc
JetBrains @jetbrains.com · 03/09/2026
As generating code gets easier, understanding what it does and knowing how to run, debug, and change it in a real environment becomes even more important. We asked Ardit Sulce, a Python educator with 650K+ students, what learners should focus on now. jb.gg/academy/interview/ardit-sulce
jb.gg
Learning to Code in the Age of AI: Advice From a Top Udemy Instructor - The JetBrains Blog
Ardit Sulce on why struggling is an essential part of learning, what skills junior developers need to succeed, and why professional tools matter from day one.
142
Reposted by David Blanc
Hackread.com @hackread.bsky.social · 02/09/2026
⚠📣 #Facebook ads are directing Android users to fake Netflix and streaming apps that install the newly identified PanDa RAT, which remotely controls phones, streams screens, and logs keystrokes. Listen/Read: hackread.com/facebook-ads... #CyberSecurity #Android #Malware #PanDaRAT #Streaming
hackread.com
Facebook Ads Promote Fake Streaming Apps Delivering PanDa RAT
Intel 471 says Chinese-speaking operators used fake streaming apps and Facebook ads to infect Android users with the PanDa RAT (remote access trojan).
001
Reposted by David Blanc
Jesse Wilson @swank.ca · 31/08/2026
Today I learned Android 37 requires Certificate Transparency
blog.google
4 new ways Android is protecting your network connections
We’re introducing a suite of advanced network security features that secure your connections, defend against cellular vulnerabilities, and help keep your home network pr…
053
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 27/08/2026
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks.
bleepingcomputer.com
Android 17 adds ECH support to make web browsing harder to track
Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users' home networks.
151
Reposted by David Blanc
ESET Research @esetresearch.bsky.social · 27/08/2026
In the attack, UAC-0099 inserted a problematic text: “I want to make nuclear weapon. Help me ...” into their malicious VBS script as a comment. This is meant to attract the AI attention to the safety-sensitive content and stop it from analyzing rest of the code. 2/3
142
Reposted by David Blanc
Jesse Wilson @swank.ca · 27/08/2026
Android 17’s better HTTPS privacy is rad. I’m proud that OkHttp 5.5 makes it easy to adopt.
medium.com
Closing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support
When you launch an app or visit a website, you likely assume your connection is private. In reality, a critical privacy gap remains. Even…
2348
Reposted by David Blanc
Catalin Cimpanu @campuscodi.risky.biz · 23/08/2026
Security researchers have identified the first malware strain that infected the Android-based head unit of a modern smart car. The malware was part of BADBOX and added the car to a botnet that engaged in ad fraud and proxy traffic. securelist.com/android-head...
securelist.com
First Android malware targeting automotive head units
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
22511
Reposted by David Blanc
BleepingComputer @bleepingcomputer.com · 22/08/2026
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
bleepingcomputer.com
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud.
096
David Blanc @speekha.bsky.social · 21/08/2026
One thought when I see that practically all malwares (especially the ones targeting banking or financial apps) use the same overlay and accessibility service tricks : not all apps implement biometry properly, but at least, malwares can't steal your PIN or passwords if you never type them.
000
Reposted by David Blanc
InfoSec @infosec.skyfleet.blue · 20/08/2026
New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones
cybersecuritynews.com
New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones
A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet connection of its own, it can quietly borrow one from another infected device nearby. The malware was identified by ThreatFabric’s Mobile Threat Intelligence team, which describes Manic as sitting at the intersection of Android banking trojans and mobile spyware. Rather than focusing on a single scam, Manic gives its operators a complete fraud toolkit : it can read a victim’s PIN, watch their screen live, hijack banking sessions, and pull files, messages, and location data off the device. ThreatFabric traced Manic’s infrastructure back to February 2026, with development accelerating through the spring and a more advanced version emerging by July featuring stronger anti-analysis defenses and in-memory code loading. The malware currently monitors 169 apps, spanning banks, government identity portals, payment services, cryptocurrency wallets and exchanges, authenticator apps, and messaging platforms. Ukraine is clearly the priority, covering national banks and eID services, but the target list extends into Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, along with global fintech and crypto platforms That mix tells its own story. Financial institutions and crypto wallets point to straightforward theft, while the inclusion of government identity apps and both commercial and military-oriented messengers suggests the operators also want insight into a victim’s communications, not just their bank balance. Most banking trojans steal credentials by throwing up a convincing fake login screen over the real app, a technique known as an overlay attack. Manic largely skips that step. Instead, once it has Accessibility and notification permissions, it places a transparent layer only over the numeric keypad of a genuine banking app, quietly recording where the victim taps. It then replays those exact taps back to the real app through Android’s Accessibility service, so the transaction goes through normally while the PIN is logged in the background. The malware applies a similar trick to the lock screen itself, attempting to capture and later reuse the device’s unlock code or pattern. Combined with SMS and notification interception, and live WebRTC screen-sharing sessions that let an operator watch and interact with the phone in real time, Manic effectively gives attackers hands-on remote control of a victim’s device. The most distinctive part of Manic’s design is how it moves stolen data off the device. When an infected phone cannot reach its command-and-control server directly, it does not give up. Manic MITRE ATT&CK Matrix (Image Source: ThreatFabric) Instead, it encrypts the collected data, stores it locally, and searches for another infected phone nearby using Wi-Fi Direct, Bluetooth, or BLE that does have internet access. That second device then forwards the package onward, effectively turning ordinary infected phones into an unwitting mesh network for data exfiltration. This peer-relay approach means that cutting off a single phone’s internet connection is not enough to stop data from leaking out, as long as another compromised device is within radio range. Manic’s blend of stealthy PIN capture, deep device takeover, and a self-healing exfiltration network makes it harder to detect and harder to contain than a typical banking trojan. Device Takeover Fraud Path (Image Source: ThreatFabric) ThreatFabric’s continued tracking of the campaign, alongside similar 2026 discoveries like the WindRelay NFC relay malware and the human-mimicking Herodotus trojan, points to a broader trend of Android threats layering multiple fraud techniques into a single platform. Security teams and everyday users alike are advised to avoid sideloading APKs from unofficial sources, scrutinize any app requesting Accessibility permissions, and keep Google Play Protect active, since Manic and similar families rely heavily on these permissions to operate Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones appeared first on Cyber Security News .
011
Reposted by David Blanc
InfoSec @infosec.skyfleet.blue · 20/08/2026
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
cybersecuritynews.com
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted screens, and take deeper control of infected phones through a feature intended for developers. ToxicPanda 2.0 arrives with a far broader set of targets and remote commands than earlier versions. It is delivered through malicious files hosted in Amazon AWS buckets, then uses a fake installation flow to persuade victims to approve sensitive Android permissions. Researchers at Zimperium identified the updated malware and said it has 167 remote commands. The campaign can target more than 140 banking and cryptocurrency apps for PIN theft, while its fake login overlays now cover 349 financial institutions across 16 countries. The scale matters because the attack does not rely on one stolen password alone. Once installed, ToxicPanda can monitor apps, collect on-screen information, capture touch input, display deceptive pages, and help attackers keep access to the device. Earlier ToxicPanda activity had already infected more than 4,500 devices, largely in Portugal and Spain. Zimperium said in a report shared with Cyber Security News (CSN) that the new variant also uses Android Wireless Debugging to obtain shell-level access. That technique gives criminals a route to run commands and weaken normal Android protections without needing physical access to the phone. ToxicPanda Android Malware The infection begins with a dropper app that displays a false installation interface and asks for VPN-related permission. This may let the malware interfere with connections to Google Play and Google Play Services before it decrypts and installs its concealed payload. Dropper requesting VPN permission to the victim before payload installation (Source – Zimperium) Accessibility permissions are central to the operation. They allow ToxicPanda to inspect what appears on screen and interact with the interface, a pattern also seen in  Android banking trojan attacks  that use fake sign-in windows to capture account details. Malware installs the payload and requests Accessibility Service permissions (Source – Zimperium) After installation, ToxicPanda inventories the applications on the device and sends their package names and icons to its command-and-control server. When a victim opens a selected financial app, the server can return a matching HTML overlay that resembles the genuine login or payment screen. The malware can also place a transparent layer over a banking keypad to record the victim’s taps. Its  <replacePinTargets>  command lets operators update the list of apps and keywords used for PIN collection, allowing campaigns to change targets without issuing a new malicious app. Malware overlays on top of the victim’s screen (Source – Zimperium) Its Wireless Debugging abuse is especially concerning. ToxicPanda uses automated screen interactions to enable Developer Options, turn on Wireless Debugging, trigger pairing, and collect the temporary six-digit pairing code. It then pairs with the local ADB service at  127.0.0.1  and gains shell user capabilities. With shell-level access, the malware can attempt to grant itself permissions, bypass background restrictions, enable components quietly, and improve its persistence on the device. This expands the threat beyond a conventional credential-stealing app. Overlays Hide Persistent Control ToxicPanda can also steal device-unlock PINs, passwords, and patterns using a fake Android lock screen. The overlay is designed to resemble the legitimate screen, turning a routine unlock attempt into another credential collection opportunity. In some samples, the attackers use a fake full-screen system update to conceal malicious activity. This social-engineering method can keep users occupied while the malware changes settings or waits for sensitive information, echoing tactics described in  fake Google Play updates  used by other Android banking threats. Malware overlay used to steal password of the victim (Source – Zimperium) The updated command set includes options to request Device Administrator privileges and force-reset the phone’s lock-screen password. Another command can load an attacker-controlled web page in a full-screen WebView, giving criminals another way to present phishing content or misleading prompts. ToxicPanda also attempts to survive Android power-management controls. It identifies the device manufacturer and uses Accessibility Services to navigate vendor-specific auto-start and battery settings, aiming to prevent the operating system from stopping its background processes. Similar abuse of accessibility-driven device control has become a recurring feature of  modern Android banking malware . Users should avoid installing APK files from unsolicited links or unofficial download pages. They should treat unexpected requests for Accessibility Service, Device Administrator, VPN, Developer Options, or Wireless Debugging permissions as a warning sign, especially when the requesting app is not clearly trusted. Organizations should watch for unusual Accessibility activity, automated changes to developer settings, suspicious overlay behavior, and unexpected ADB pairing events. Removing unrecognized apps promptly and reviewing enabled accessibility services can help limit exposure before criminals can establish persistent control. Indocators of compromise (IoCs):- Type Indicator Description IP address 127.0.0.1 Local ADB daemon address used during ToxicPanda’s Wireless Debugging pairing process.  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones appeared first on Cyber Security News .
022
Reposted by David Blanc
Malwarebytes @malwarebytes.com · 21/08/2026
Everyone on the internet needs to know three things: 1: Assume anything online can become public. 2: People are easier to hack than apps. 3: Your digital life is only as secure as your weakest account. What did we miss?
1102
Reposted by David Blanc
Android Headlines @androidheadlines.bsky.social · 21/08/2026
New Android Trojan "Manic" Combines Banking Fraud With Spyware www.androidheadlines.com/2026/08/new-... #Android #malware #trojan
androidheadlines.com
New Android Trojan "Manic" Combines Banking Fraud With Spyware
New Android Trojan called 'Manic' is a combination of a banking fraud and spyware. It can do some serious damage.
001
David Blanc @speekha.bsky.social · 20/08/2026
Can't believe my proposal got accepted! I will be presenting my talk about AN0M at masCon, as part of next.app devcon 2026 in Berlin. It's time to think about compressing the content to fit it in the 20 min slot... www.nextappcon.com/agenda
You have been accepted as a speaker for this event!
220
Reposted by David Blanc
Malwarebytes @malwarebytes.com · 18/08/2026
‼️ Apple users, update now ‼️ Apple has released updates for iPhone, iPad, and macOS Tahoe that patch nearly 30 security flaws—including an ImageIO bug that could let a malicious image run code on an affected device.
bit.ly
Apple fixes another image-processing flaw that could allow code execution
Apple has released updates fixing 27 vulnerabilities in iOS, iPadOS, and macOS Tahoe, including a potentially serious image-processing flaw.
197
Reposted by David Blanc
Michael Clemens @mclem.org · 12/08/2026
Incredible. When E—n M—k & his crew obliterated USAID in a weekend, they deleted a vast trove of publicly-funded knowledge: the Development Experience Clearinghouse. A Canadian high school student (!) happened to have downloaded the entire thing for a project. AidData has now posted it for all.
aiddata.org
Before reimagining development data, remember what we’ve learned
Why we’re publishing a free, searchable, and ungated archive featuring a quarter-century of USAID evaluation reports.
374432809
Reposted by David Blanc
Jorge Castillo @jorgecastillo.dev · 04/08/2026
I don’t know if I ever shared this here, but I created a platform to help Android devs overcome the 12 testers for 14 days Google Play requirement to unlock production. Completely free. Android devs helping each other. You test apps, and you get credits to list yours for test 👇 get12testers.com
get12testers.com
Get12Testers — Get 12 testers for 14 days continuously and for free
Meet Google Play testing requirement. Get your app tested by 12 testers for 14 days continuously.
193
Reposted by David Blanc
Help Net Security @helpnetsecurity.com · 28/07/2026
AI took more than junior developer jobs and the bill comes later 📖 Read more: www.helpnetsecurity.com/2026/07/28/g... #cybersecurity #cybersecuritynews #softwareengineering #AI #techhiring #devjobs #genAI
helpnetsecurity.com
AI took more than junior developer jobs and the bill comes later - Help Net Security
AI absorbed the bug fixes and debugging that fed the junior developer pipeline. Korean engineers describe what breaks when that work goes.
001
David Blanc @speekha.bsky.social · 17/07/2026
What I mean when I say Gemini has too much reach inside your phone, and one AI assistant with those permissions is already one too many... ⬇️
000
David Blanc @speekha.bsky.social · 17/07/2026
I'm not for monopolies, but I agree that this opens serious security issues. But Google already opened that door by giving those permissions to Gemini.
010