Android
Advanced Espionage Tool Adware AI Android APP APPX file ATM Malware Backdoor Banking Bookit Bot BotNet Code-injection CoinMiners Crypt Cryptocurrency Cryptojacking CyberSpy Data Wiper DDoS DEAMON Destructive Malware DNS Backdoor Downloader Driver Droper EDR and AV Killer ELF ENGINE Espionage Exploit Families Fileless FRAMEWORK FUD Engine Go GPT GPU GRU Malware HTML ICS InfoStealer Injector iOS IoT IRC ISS Java JavaScipt JSON Keylogger Killer Kit LINUX Loader Maas MacOS Macro Malware Military Malware Miner Mobil MultiOS nmp OS OSX OT malware P2P virus Password STEALER Pay-per-install (PPI) PoS Malware PowerShell Program PyPI Python QR trojan Ransom Raspberry RAT Roque Rootkit SMS Spy Spyware SQL Malware Stealer SymbOS Tool Trojan TV UEFI bootkit USB Utility VBA Macro VBE VBS VHD malware Virus Vishing toolset VMware ESXi Windows Wipper WM virus Worm Wrapper
| 20.08.26 | ToxicPanda | The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile | MALWARE | ANDROID |
| 20.08.26 | GoldDigger | Striking gold: Inside the GoldDigger Android malware | MALWARE | ANDROID |
| 29.07.26 | Flying Eagle | Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon | MALWARE | ANDROID RAT |
| 08.07.26 | RedWing | RedWing: A Mobile Malware-as-a-Service Operation | MALWARE | ANDROID |
| 04.07.26 | TONResolver RAT | In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. | MALWARE | ANDROID |
| 04.07.26 | Arsink RAT | The SonicWall Capture Labs threat research team identified an ongoing Android Remote Access Trojan (RAT) campaign that employs multiple techniques to harvest sensitive user information through phishing and data exfiltration activities by impersonating the actual app icons and using similar names. | MALWARE | ANDROID |
| 14.06.26 | NFCShare | NFCShare Android Trojan: NFC card data theft via malicious APK | MALWARE | ANDROID |
| 12.05.26 | TrickMo | New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps | MALWARE | ANDROID |
| 14.04.26 | Mirax | Mirax: a new Android RAT turning infected devices into potential residential proxy nodes | MALWARE | ANDROID RAT |
|
21.03.26 |
Keenadu malware gives an attacker control over a device but appears to be used primarily to facilitate ad fraud |
ANDROID |
||
|
20.03.26 |
Perseus: DTO malware that takes notes |
ANDROID |
||
|
16.03.26 |
Stealthy Backdoor Attack to Real-world Models in Android Apps |
ANDROID |
||
|
12.03.26 |
BeatBanker: A dual‑mode Android Trojan |
Android |
||
|
21.02.26 |
Android.Phantom trojans are bundled with modded games and popular apps to infiltrate smartphones. They use machine learning and video broadcasts to engage in click fraud |
ANDROID |
||
|
20.02.26 |
PromptSpy ushers in the era of Android threats using GenAI |
ANDROID |
||
|
24.12.25 |
Choose Your Fighter: A New Stage in the Evolution of Android SMS Stealers in Uzbekistan |
ANDROID |
||
|
24.12.25 |
NexusRoute: Attempting to Disrupt an Indian Government Ministry |
ANDROID |
||
|
18.12.25 |
Kimsuky Distributing Malicious Mobile App via QR Code |
ANDROID |
||
|
08.12.25 |
Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases |
ANDROID |
||
|
08.12.25 |
New FvncBot Android banking trojan targets Poland |
ANDROID |
||
|
02.12.25 |
Albiriox Exposed: A New RAT Mobile Malware Targeting Global Finance and Crypto Wallets |
Android |
||
|
20.11.25 |
Sturnus: Mobile Banking Malware bypassing WhatsApp, Telegram and Signal Encryption |
Andorid banking |
||
|
08.11.25 |
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices |
ANDROID |
||
|
01.11.25 |
Investigation Report: Android/BankBot-YNRK Mobile Banking Trojan Executive Summary This report covers the analysis and findings related to three Android application packages (APKs) |
Android |
||
|
29.10.25 |
New Android Malware Herodotus Mimics Human Behaviour to Evade Detection |
Android |
||
|
25.10.25 |
Sophisticated Android malware that mines crypto and silently steals banking credentials. EXECUTIVE SUMMARY CYFIRMA is dedicated to providing advanced warning and strategic |
Android |
||
|
05.10.25 |
Klopatra: exposing a new Android banking trojan operation with roots in Turkey |
Android |
||
|
09.09.25 |
The Rise of RatOn: From NFC heists to remote control and ATS |
ANDROID |
||
|
02.09.25 |
Android Droppers: The Silent Gatekeepers of Malware |
Android |
||
|
30.08.25 |
Android Document Readers and Deception: Tracking the Latest Updates to Anatsa |
Android |
||
|
30.08.25 |
Android backdoor spies on employees of Russian businesses |
Android |
||
|
17.08.25 |
Hunt.io Exposes and Analyzes ERMAC V3.0 Banking Trojan Full Source Code Leak |
Android |
||
|
14.08.25 |
PhantomCard: New NFC-driven Android malware emerging in Brazil |
Android |
||
|
22.07.25 |
Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict |
ANDROID |
||
|
03.06.25 |
Crocodilus Mobile Malware: Evolving Fast, Going Global |
Android |
||
|
22.04.25 |
A novel Android malware offered through a Malware-as-a-Service (MaaS) model, enabling NFC relay attacks for fraudulent cash-outs. |
ANDROID |
||
|
16.04.25 |
Nice chatting with you: what connects cheap Android smartphones, WhatsApp and cryptocurrency theft? |
Android |
||
|
29.03.25 |
Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices |
ANDROID |
||
|
20.03.25 |
Virtue or Vice? A First Look at Paragon’s Proliferating Spyware Operations |
Android |
||
|
08.03.25 |
Satori Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes |
Android |
||
|
27.02.25 |
Android trojan TgToxic updates its capabilities |
Android |
||
|
10.02.25 |
Take my money: OCR crypto stealers in Google Play and App Store |
Android |
||
|
16.12.24 |
“A Digital Prison”: Surveillance and the suppression of civil society in Serbia |
ANDROID |
||
|
12.12.24 |
Lookout Discovers Two Russian Android Spyware Families from Gamaredon APT |
ANDROID |
||
|
12.12.24 |
Lookout Discovers Two Russian Android Spyware Families from Gamaredon APT |
ANDROID |
||
|
06.12.24 |
DroidBot: Insights from a new Turkish MaaS fraud operation |
ANDROID |
||
|
04.11.24 |
As part of our ongoing mission to identify emerging threats to mobile security, ... |
ANDROID |
||
|
24.09.24 |
Octo2: European Banks Already Under Attack by New Malware Variant |
Android |
||
|
09.09.24 |
New Android SpyAgent Campaign Steals Crypto Credentials via Image Recognition |
Android |
||
|
26.08.24 |
NGate Android malware relays NFC traffic to steal cash |
Android |
||
|
06.08.24 |
LianSpy: new Android spyware targeting Russian users |
Android |
||
|
09.07.24 |
Lookout Discovers Houthi Surveillanceware Targeting Middle Eastern Militaries |
Android |
||
|
01.07.24 |
CapraTube Remix | Transparent Tribe’s Android Spyware Targeting Gamers, Weapons Enthusiasts |
Android |
||
|
01.07.24 |
Beware of Snowblind: A new Android malware |
Android |
||
|
30.05.24 |
AhMyth is malware that spreads through a few different infection vectors and uses various means to collect and exfiltrate sensitive information from infected devices. |
Android |
||
|
10.05.24 |
Coper is a descendant of ExoBotCompat, which was a rewritten version of Exobot. |
Android |
||
|
27.04.24 |
Brokewell: do not go broke from new banking malware! |
Android |
||
|
01.04.24 |
Android Malware Vultur Expands Its Wingspan |
Android |
||
|
31.03.24 |
The authors behind Android banking malware Vultur have been spotted adding new technical features, ... |
Android |
||
|
22.03.24 |
AndroxGh0st is a Python-based malware designed to target Laravel applications. |
Android |
||
|
13.03.24 |
PixPirate: The Brazilian financial malware you can’t see |
Android |
||
|
19.02.24 |
Anatsa Trojan Returns: Targeting Europe and Expanding Its Reach |
Android |
||
|
09.02.24 |
MoqHao evolution: New variants start automatically right after installation |
Android |
||
|
06.02.24 |
Skygofree: Following in the footsteps of HackingTeam |
Android |
||
|
18.01.24 |
CISA and FBI Release Known IOCs Associated with Androxgh0st Malware |
Android |
||
|
27.12.23 |
Stealth Backdoor “Android/Xamalicious” Actively Infecting Devices |
Android |
||
|
24.12.23 |
Android Banking Trojan Chameleon can now bypass any Biometric Authentication |
Android |
||
|
11.12.23 |
Beware of predatory fin(tech): Loan sharks use Android apps to reach new depths |
Android |
||
|
01.12.23 |
Promon discovers new Android banking malware, “FjordPhantom” |
Android |
||
|
21.11.23 |
Enchant malware uses the Accessibility Service feature to target specific cryptocurrency wallets, including imToken, OKX, Bitpie Wallet, and TokenPocket wallet. |
Android |
||
|
11.11.23 |
Unlucky Kamran: Android malware spying on Urdu-speaking residents of Gilgit-Baltistan |
Android |
||
|
06.11.23 |
Droppers are a specific category of malware whose main purpose is to install a payload on an infected device. |
Android |
||
|
01.11.23 |
Arid Viper disguising mobile spyware as updates for non-malicious Android applications |
Android |
||
|
16.10.23 |
The malware has been released on github at https://github.com/EVLF/Cypher-Rat-Source-Code |
Android |
||
|
05.10.23 |
Let's dig deeper: dissecting the new Android Trojan GoldDigger with Group-IB Fraud Matrix |
Android |
||
|
05.10.23 |
Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 |
Android |
||
|
05.10.23 |
Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 |
Android |
||
|
03.10.23 |
According to cyware, Zanubis malware pretends to be a
malicious PDF application. The threat actor uses it as a key to decrypt
|
Android |
||
|
19.09.23 |
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. |
Android |
||
|
31.08.23 |
ESET researchers have discovered active campaigns linked
to the China-aligned APT group known as GREF, distributing espionage
code |
Android |
||
|
03.08.23 |
SharkBot is a piece of malicious software targeting Android Operating Systems (OSes). |
Android |
||
|
30.07.23 |
Trend Micro’s Mobile Application Reputation Service
(MARS) team discovered two new related Android malware families involved
in cryptocurrency- |
Android |
||
|
22.07.23 |
Hunting the AndroidBianLian botnet |
Android |
||
|
19.07.23 |
Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 |
Android |
||
|
19.07.23 |
Lookout Attributes Advanced Android Surveillanceware to Chinese Espionage Group APT41 |
Android |
||
|
04.07.23 |
Neo_Net has been conducting an eCrime campaign targeting clients of prominent banks globally, with a focus on Spanish and Chilean banks.. |
Android |
||
|
30.06.23 |
According to Check Point, this malware features several malicious Android applications that mimic legitimate applications... |
Android |
||
|
30.06.23 |
Polish security research blog Niebezpiecznik, which first reported the breach and analyzed a dump of the stolen data.. |
Android |
||
|
30.05.23 |
Predator: Looking under the hood of Intellexa’s Android spyware |
Android |
||
|
25.05.23 |
It is rare for a developer to upload a legitimate app, wait almost a year, and then update it with malicious code. |
Android |
||
|
19.05.23 |
It's worth noting that the same technique of modifying the zygote process has also been adopted by another mobile trojan called Triada. |
Android |
||
|
06.05.23 |
Nexus is the name of a banking trojan targeting Android Operating Systems (OSes). |
Android |
||
|
06.05.23 |
Predator is the name of spyware (malicious software) targeting Android users. |
Android |
||
|
06.05.23 |
Goldoson is an Android malware that compiles a list of
installed applications and records the history of Wi-Fi and Bluetooth
devices, |
Android |
||
|
06.05.23 |
Chameleon is the name of a trojan targeting Android Operating Systems (OSes). |
Android |
||
|
06.05.23 |
Fleckpe is a recently discovered Android Trojan family found on Google Play, which secretly subscribes victims to paid services. |
Android |
||
|
05.05.23 |
New ransomware posing as COVID‑19 tracing app targets Canada; ESET offers decryptor |
Android |
||
|
05.05.23 |
Scarcruft Bolsters Arsenal for targeting individual Android devices |
Android |
||
|
20.04.23 |
Malware Analysis Report (AR19-252A) |
Android |
||
|
11.04.23 |
BEWARE: SOVA ANDROID BANKING TROJAN EMERGES MORE POWERFUL WITH NEW CAPABILITIES |
Android |
||
|
4.4.23 |
Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware |
Android |
||
|
18.03.23 |
The mobile malware landscape of the LATAM region, more
specifically Brazil, has recently risen to prominence in the news due to
|
|||
|
18.03.23 |
Between the end of 22 and the beginning of 23, a new Android banking trojan was discovered by the Cleafy TIR team. |
|||
|
18.02.23 |
The malware has multiple stages, payloads and exfiltrates
data from the Android device continually. Below, we describe in simple
steps how |
Android |
||
|
14.02.23 |
First clipper malware discovered on Google Play |
Android |
||
|
22.01.23 |
Wroba to infiltrate Wi-Fi routers and undertake Domain Name System (DNS) hijacking. |
Android |
||
|
22.01.23 |
Wroba to infiltrate Wi-Fi routers and undertake Domain Name System (DNS) hijacking. |
Android |
||
|
18.05.22 |
Fake Mobile Apps Steal Facebook Credentials, Cryptocurrency-Related Keys |
Android |
||
|
10.05.22 |
Joker, a repeat offender, refers to a class of harmful
apps that are used for billing and SMS fraud, while also performing a
number of |
Android |
||
|
10.01.23 |
This StrongPity backdoor has various spying features: its
11 dynamically triggered modules are responsible for recording phone
calls, |
Android Backdoor |
||
|
24.12.25 |
Frogblight threatens you with a court case: a new Android banker targets Turkish users |
ANDROID BANKING |
||
|
05.08.24 |
BlankBot - a new Android banking trojan with screen recording, keylogging and remote control capabilities |
Android Banking |
||
|
18.04.24 |
SoumniBot: the new Android banker’s unique techniques |
Android Banking |
||
|
24.12.25 |
Meet Cellik - A New Android RAT With Play Store Integration |
ANDROID RAT |
||
|
11.04.25 |
Newly Registered Domains Distributing SpyNote Malware |
Android RAT |
||
|
28.03.25 |
PJobRAT makes a comeback, takes another crack at chat apps |
ANDROID RAT |
||
|
30.09.23 |
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor. |
Android RAT |
||
|
30.09.23 |
Androrat is a remote administration tool developed in Java Android for the client side and in Java/Swing for the Server. |
Android RAT |
||
|
31.08.23 |
The Trend Micro Mobile Application Reputation Service
(MARS) team discovered a new, fully undetected Android banking trojan,
|
Android RAT |
||
|
09.01.23 |
Android Spyware is one of the most common kinds of malware used by attackers to gain access to personal data and carry out fraud operations. |
Android RAT |
||
|
20.05.22 |
Google's Threat Analysis Group (TAG)
on Thursday pointed fingers at a North Macedonian spyware developer
named Cytrox for |
Android Spyware |
||
|
14.06.22 |
How SeaFlower 藏海花 installs backdoors in iOS/Android web3 wallets to steal your seed phrase |
Android/iOS |