ZCyberNews
中文

#android

13 articles

Mirax, NGate, and TrickMo were the most active threat actors targeting Android devices between April and July 2026, according to 16 articles on the tag. Key vulnerabilities included CVE-2026-8566, CVE-2026-8568, CVE-2023-4863, and CVE-2025-54957, with two rated critical and ten high severity. Affected sectors spanned cryptocurrency, technology, consumer electronics, financial services, and consumer markets, while reported incidents impacted users globally, with specific activity in Europe, Austria, Brazil, and France.

Screenshot of a browser-based ransomware page displaying a ransom note after encrypting local files on Android Chrome.HIGH
Malware

Browser-Only Ransomware Exploits Chrome File System API via

Check Point Research found a DeepSeek-generated sample using Chrome's File System Access API to encrypt Android photo directories — no native payload or exploit required.

4 min read
Pixel 10 VPU Driver Bug Lets Userspace Map Kernel MemoryHIGH
Vulnerabilities

Pixel 10 VPU Driver Bug Lets Userspace Map Kernel Memory

Google Project Zero found a Pixel 10 VPU driver flaw allowing userspace to map arbitrary physical memory, including the kernel image. Exploit required 5 lines of code.

CVE-2025-54957
4 min read
Chrome 148 Patches AI Site Isolation Bypass, Android Payment FlawHIGH
Vulnerabilities

Chrome 148 Patches AI Site Isolation Bypass, Android Payment Flaw

CVE-2026-8568 (CVSS 3.1) lets attackers bypass Chrome Site Isolation via AI features after renderer compromise; CVE-2026-8566 (CVSS 4.3) targets Android Payments.

CVE-2026-8568CVE-2026-8566
3 min read
TrickMo Android Trojan Uses TON Blockchain for C2, SOCKS5 PivotsHIGH
Malware

TrickMo Android Trojan Uses TON Blockchain for C2, SOCKS5 Pivots

ThreatFabric tracked a TrickMo variant using The Open Network (TON) for C2 and SOCKS5 proxies to pivot into victim networks, targeting banking and crypto users in France, Italy,...

3 min readTrickMo
Mobile App Permissions Still Expose Users to Privacy RisksMEDIUM
Industry News

Mobile App Permissions Still Expose Users to Privacy Risks

ESET analysis shows 1 in 3 Android apps request unnecessary permissions — location, camera, microphone — enabling data harvesting and surveillance. Users should audit permissions.

2 min read
NGate Malware Trojanizes HandyPay App to Steal Brazilian NFC DataHIGH
Malware

NGate Malware Trojanizes HandyPay App to Steal Brazilian NFC Data

NGate malware, using AI-generated code, has infected the legitimate HandyPay NFC app to steal payment card data and PINs from over 220,000 Android users in Brazil, according to ESET.

3 min readNGate
NGate Malware Uses AI to Evade Detection in Trojanized NFC AppsHIGH
Malware

NGate Malware Uses AI to Evade Detection in Trojanized NFC Apps

NGate malware version 2.0, built with AI assistance, hides in a trojanized NFC payment app to steal SMS, contacts, and crypto wallet data from Android devices while evading security software.

3 min read
MiningDropper Framework Delivers Infostealers, RATs to Android DevicesHIGH
Malware

MiningDropper Framework Delivers Infostealers, RATs to Android Devices

MiningDropper, a multi-stage Android malware framework, delivers infostealers, RATs, and banking trojans to devices via disguised apps, according to CyberSecurity News researchers.

3 min read
Mirax Android RAT Infects 220,000 Users via Meta Ads, Creates SOCKS5 ProxyHIGH
Malware

Mirax Android RAT Infects 220,000 Users via Meta Ads, Creates SOCKS5 Proxy

Mirax Android RAT reached over 220,000 users via Meta ads, turning infected devices into SOCKS5 proxies for threat actors to route malicious traffic and steal data from Spanish-speaking victims.

3 min readMirax
Google Tightens Android 17 Privacy Rules, Blocks 8.3 Billion Ads in 2025INFORMATIONAL
Industry News

Google Tightens Android 17 Privacy Rules, Blocks 8.3 Billion Ads in 2025

Google announced new Android 17 privacy policies restricting contact and location data access, while its 2025 ad safety report details the blocking of 8.3 billion policy-violating ads and 24.9 million advertiser account suspensions.

4 min read
Mirax Android RAT Evolves with Proxy Network and Data Theft CapabilitiesHIGH
Malware

Mirax Android RAT Evolves with Proxy Network and Data Theft Capabilities

The Mirax Android RAT is being offered as a Malware-as-a-Service to Russian-speaking affiliates, ensnaring devices in Europe into a residential proxy network while stealing credentials and sensitive data.

5 min read
Mirax Android RAT Steals Credentials, Enslaves Phones for Proxy NetworkHIGH
Malware

Mirax Android RAT Steals Credentials, Enslaves Phones for Proxy Network

The Mirax Android RAT steals banking credentials and covertly turns infected devices into residential proxy nodes for criminal traffic, creating a dual-threat mobile botnet.

4 min read
Critical Android SDK Flaw Exposed Millions of Crypto Wallet Private KeysCRITICAL
Vulnerabilities

Critical Android SDK Flaw Exposed Millions of Crypto Wallet Private Keys

A vulnerability in the EngageLab Push SDK, tracked as CVE-2023-4863, allowed attackers to steal private keys from millions of Android cryptocurrency wallets by intercepting push notifications.

CVE-2023-4863
3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.