Mobile
Mobile-platform vulnerabilities and the spyware ecosystem that exploits them — from Pegasus-class commercial surveillance tooling to opportunistic Android malware. Covers OS-level flaws in iOS and Android and the mobile-specific attack surface: baseband, MDM, and sideload channels.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

Android Malware Relays NFC Cards, Takes Out Loans
WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.

Flying Eagle Android RAT Source Code Leaks to Telegram
Flying Eagle Android RAT source code is circulating on Telegram. Hunt.io traced 170 C2 servers. Block sideloading and audit your MDM policy.

Android AI agent frameworks: overlay text pivots to host
Zhang et al. published seven attacks against five open-source Android agent frameworks. 2% opacity overlay text feeds prompts to the vision model; unsanitized ADB commands pivot to the host PC.

RedHook Android RAT pairs Wireless ADB on-device
Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.
281 free Android VPN apps: 29 leak, 246 track
MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

281 free Android VPNs, and a familiar audit outcome
A new study of 281 popular free Android VPN apps found traffic leaks, missing encryption, and tracking. The category has kept failing this test for years.

RedWing turns Android bank fraud into a Telegram rental
Zimperium's zLabs details RedWing, an Android bank-fraud MaaS sold on Telegram — Oblivion variant, subscription tiers, prebuilt droppers, 82 target banks.

Pegasus on the MEP investigating Pegasus
Citizen Lab's forensic analysis found that former European Parliament member Stelios Kouloglou was repeatedly infected with NSO Group's Pegasus spyware while serving on the committee tasked with investigating that industry.