Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Mobile

Mobile-platform vulnerabilities and the spyware ecosystem that exploits them — from Pegasus-class commercial surveillance tooling to opportunistic Android malware. Covers OS-level flaws in iOS and Android and the mobile-specific attack surface: baseband, MDM, and sideload channels.

0 CVEs9 articlesRSS
Articles
~/articles/2026-08-23-banking-trojans-manic-grandoreiro-toxicpanda
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
● Breaking
mobile

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

read →
~/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud
Android Malware Relays NFC Cards, Takes Out Loans
mobile

Android Malware Relays NFC Cards, Takes Out Loans

WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.

read →
~/articles/2026-07-29-flying-eagle-android-rat-telegram-leak
Flying Eagle Android RAT Source Code Leaks to Telegram
mobile

Flying Eagle Android RAT Source Code Leaks to Telegram

Flying Eagle Android RAT source code is circulating on Telegram. Hunt.io traced 170 C2 servers. Block sideloading and audit your MDM policy.

read →
~/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot
Android AI agent frameworks: overlay text pivots to host
mobile

Android AI agent frameworks: overlay text pivots to host

Zhang et al. published seven attacks against five open-source Android agent frameworks. 2% opacity overlay text feeds prompts to the vision model; unsanitized ADB commands pivot to the host PC.

read →
~/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000
RedHook Android RAT pairs Wireless ADB on-device
mobile

RedHook Android RAT pairs Wireless ADB on-device

Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

read →
~/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking
281 free Android VPN apps: 29 leak, 246 track
Analysis
mobile

281 free Android VPN apps: 29 leak, 246 track

MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

read →
~/articles/2026-07-10-android-free-vpn-study-familiar-audit-outcome
281 free Android VPNs, and a familiar audit outcome
Analysis
mobile

281 free Android VPNs, and a familiar audit outcome

A new study of 281 popular free Android VPN apps found traffic leaks, missing encryption, and tracking. The category has kept failing this test for years.

read →
~/articles/2026-07-08-redwing-android-maas-oblivion-telegram-zimperium
RedWing turns Android bank fraud into a Telegram rental
Analysis
mobile

RedWing turns Android bank fraud into a Telegram rental

Zimperium's zLabs details RedWing, an Android bank-fraud MaaS sold on Telegram — Oblivion variant, subscription tiers, prebuilt droppers, 82 target banks.

read →
~/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis
Pegasus on the MEP investigating Pegasus
Analysis
mobile

Pegasus on the MEP investigating Pegasus

Citizen Lab's forensic analysis found that former European Parliament member Stelios Kouloglou was repeatedly infected with NSO Group's Pegasus spyware while serving on the committee tasked with investigating that industry.

read →