Visualização normal

Antes de ontemGBHackers on Security | #1 Globally Trusted Cyber Security News Platform

StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover

StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026. The operation highlights the continued effectiveness of piracy-themed social engineering. Victims who clicked […]

The post StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks

Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed to combat SMS blaster campaigns that increasingly target users in public spaces. Google states the Android 17 changes focus on four […]

The post Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims

Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced […]

The post Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims

BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over […]

The post BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials

Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency […]

The post Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud

A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into rogue contactless-card readers and enable real-time, card-present fraud. Group-IB’s investigation centres on a 13-minute fraud call in which an attacker impersonating a bank employee convinced a victim to install a malicious Android app. […]

The post WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Android Banking Droppers Surge as Malware Operators Change Packaging Tactics

Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet […]

The post Android Banking Droppers Surge as Malware Operators Change Packaging Tactics appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control

Copybara is being weaponized in a new N26-themed fraud campaign in Italy that chains vishing, a real‑time phishing control kit, and a multi‑stage Android dropper to gain full remote control of victims’ phones via abused Accessibility services. The operator leverages real notifications already present in the legitimate N26 app to build trust, then pushes the […]

The post Copybara Abuses Android Accessibility for Keylogging, Screen Streaming and Remote Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌