Visualização de leitura

WeChat Worm Can Hijack Accounts Without Victims Answering Calls

Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit.

Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone.

The attack works only when the caller already appears in the victim’s WeChat contacts. Calif reported the flaw to Tencent in July, and Tencent has blocked the exploit for all users. The good news is that researchers found no evidence that attackers used the flaw in real-world attacks, but the case shows how dangerous zero-click vulnerabilities can be.

“Simply by calling a victim, WeWorm can hijack their account and call their friends, spreading from phone to phone.” reads the report at Calif. “If exploited, actors can compromise over a billion phones (or accounts), upending livelihoods and breaking communities worldwide.”

Researchers built a demo WeChat worm that spread between three test phones without requiring any action from the victims. They started with a Pixel 10a and called an iPhone 17e, exploiting the flaw while the phone was still ringing. After taking control of the iPhone, they used it to call another Pixel 10a and compromise that device too. In other words, one compromised account can become the starting point for the next attack.

The exploit works within seconds and gives the attacker full control of the victim’s WeChat account. They can read and send messages, make calls and use the account as if they were the victim. The victim does not need to answer or touch the phone. Even answering the call does not stop the attack. Declining the call blocks that attempt, but the attacker can simply try again later.

The main limitation is that the attacker must already be a WeChat contact. However, compromising one of the victim’s friends could provide a way around that restriction.

“The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep.” the researchers explain. “This exploit requires the attacker to be on the victim’s friend list. But that’s not much of a barrier: an attacker can compromise one of your friends first and use their account to reach you.”

Calif published both Android and iOS RCE demos. The firm did not disclose technical details about the issue and will present the full analysis at a conference. For now, defenders have no clear indicators to search for, and users cannot tell if attackers targeted them with a call.

Combined with other Android and iOS flaws, the attack could also lead to full device control.

Researchers say AI helped them find the flaw and build an RCE exploit in about two days. They then built the worm in another week. They argue that AI is making advanced attack capabilities available to less-skilled attackers, increasing the risk of zero-click threats.

Researchers say the goal of publishing the findings is to raise awareness and encourage governments and technology companies to work together on AI security.

The WeChat flaw comes from a memory corruption bug in the app’s VoIP system. Researchers are keeping the technical details private for now and plan to present their full analysis at a future security conference.

The team believes this bug is just one example of the unusual attack surfaces found in messaging apps. They are researching similar weaknesses in other apps and working with developers to reduce these risks. Some changes may require cooperation from platform owners. Once the work progresses, they plan to publish more details about the WeChat flaw.

In August, Tencent released versions Android 8.0.77 and iOS 8.0.76 that addressed the issue.

WeChat is Tencent’s messaging and social platform, launched in 2011 and now much more than a chat app. It lets users send messages, make voice and video calls, create group chats and share content through Moments. It also includes official accounts, video channels, games, search and Mini Programs, which provide services such as shopping, bookings and deliveries without requiring separate apps.

In China, its local version, Weixin, also integrates Weixin Pay for mobile payments. Tencent reported 1.418 billion combined monthly active users for Weixin and WeChat at the end of 2025, making the platform one of the world’s largest messaging ecosystems.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, mobile)

Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections.

A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, tracing it to an iMessage zero-click exploit and identifying high-confidence indicators of compromise between December 2025 and January 2026, with the possibility of additional infections not ruled out.

“In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware.” reads the report published by Citizen Lab. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. “

The attack required no action from the victim, which makes zero-click attacks especially dangerous. Citizen Lab said the Pegasus infection could stay hidden while giving the attacker full access to the phone, including messages, photos, notes, microphone, and camera. Apple later fixed this specific exploit through security updates in iOS 18.4.1.

“We believe that the zero-click exploit used in this attack targeted Apple iMessage, and has subsequently been patched by Apple as of iOS 18.4.1.” continues the report. “A zero-click infection with Pegasus spyware would not have been visible to the target, and would give the Pegasus attacker total access to the device. Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages. Pegasus also has the ability to covertly enable the phone’s microphone and camera.”

This one confirmed infection sits inside something considerably bigger. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026, spanning student movement members, civil society activists, an opposition member of parliament, and a local councilor, which the organization is calling the largest documented surveillance wave in Serbia’s history. Twelve people approached SHARE’s digital forensics team in August after receiving Apple’s own threat notifications, warnings the company sends when it detects likely state-sponsored spyware targeting; eleven of those devices remain presumed infected pending further forensic confirmation.

The timing lines up uncomfortably well with Serbia’s political calendar. This surveillance wave coincides with local elections held on March 29, 2026, and stretches toward planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.

“These notifications and forensic confirmation highlight the aggressive mercenary spyware targeting of the peaceful pro-democracy movement with mercenary spyware ahead of key 2026 election cycles.” continues the report.

Targeting activists and opposition figures specifically in the run-up to elections isn’t subtle, and it fits a pattern Serbia has shown before.

Serbia has a history of using commercial spyware. Citizen Lab previously documented Pegasus targeting civil society and the use of Cellebrite tools to install the locally developed NoviSpy on activists’ phones. In this case, SHARE Foundation and Amnesty Tech found a new version of NoviSpy on a student activist’s Android phone after Serbian authorities seized it during police questioning.

Amnesty International’s Security Lab head, Donncha Ó Cearbhaill, connected the dots plainly between state custody and spyware installation.

“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities” he said.

If you’ve received an Apple Threat Notification, whether in Serbia or anywhere else, the Citizen Lab’s guidance is unambiguous: treat it as a presumed infection and get expert help immediately rather than waiting to see if anything seems wrong. Individuals in Serbia should contact the SHARE Foundation directly, and anyone elsewhere can reach Access Now’s Digital Security Helpline, which supports journalists, human rights defenders, and other high-risk civil society targets worldwide. Anyone who suspects they might be a target based on their work or public role should also turn on Lockdown Mode, Apple’s built-in feature that significantly narrows what a zero-click exploit can actually reach, and keep every device updated, since the patch that closed this specific hole has already existed for well over a year for anyone who installed it.

“We believe that the zero-click used in this attack has been rendered ineffective by a patch from Apple in recent iOS versions. We urge everyone, especially those facing increased risks because of who they are or the work they do, to keep all devices updated.” concludes the report. “Click HERE for instructions on how to keep your iPhone up to date.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pegasus)

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline.

ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development as of July.

“Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features.” reads the report published by the ThreatFabric’s Mobile Threat Intelligence team. “Its targeting is strongly focused on Ukraine, covering Ukrainian banks, government and identity services, and messaging applications, while also extending to Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”

The malware monitors 169 different Android apps, including banking and payment apps across several European countries, government and eID services, crypto exchanges and wallets, 2FA tools, messaging apps, browsers and email clients.

This wide coverage appears deliberate. By targeting both financial and communication apps, the attackers can track a victim’s money, messages, location and files from the same device.

ThreatFabric traces the first infrastructure registrations back to February 2026, with development and production services appearing in late March and April. By July, an updated build had added stronger anti-analysis checks, in-memory DEX loading, and a technique the researchers call lock-secret phishing, which extracts the device PIN or pattern by presenting a fake prompt before the victim reaches the real lock screen.

Once installed, Manic requests Accessibility and notification access, then uses the Accessibility service as a UI keylogger. It classifies everything it captures before logging it: lock-screen input, recovery phrase candidates, four-to-six-digit SMS codes, passwords, long messages, email logins, and ordinary text.

“Manic uses its Accessibility service as a UI keylogger. It classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text.” continues the report. “Each key log record includes the app and package, captured text, timestamp, whether the input came from Autofill or manual entry, and whether the app is on Manic’s target list “

Each log record includes the app name and package, the captured text, a timestamp, whether input came from autofill or manual entry, and whether the app is on Manic’s target list.

The PIN theft technique works differently from a typical banking overlay. When Manic detects a numeric keypad in a targeted app, it places an invisible layer over the keys and records each tap. It then briefly passes the tap to the real keypad using Android’s Accessibility features, so the banking app works normally while Manic captures the PIN.

Another function, called autoEnterPin, can try to enter a stored PIN or pattern on the Android lock screen. This gives attackers two options: capture a PIN during a banking session and later use it to unlock the device without the victim being present.

According to the researchers, Manic stands out for its offline relay.

“Manic uses a store-and-forward relay mechanism to exfiltrate data even when the infected device cannot reach the C2 server directly.” continues the report. “Collected files and command results are encrypted with AES-GCM and placed in a local queue, allowing the source device to remain offline while the malware searches for another infected device that can provide a route to the C2 infrastructure.”

Manic searches for nearby infected devices over Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, and supports chains of up to four relay hops. Cutting an infected phone off from the Internet doesn’t cut it off from exfiltration, as long as another infected device is within radio range. It’s a store-and-forward mesh built out of other people’s compromised phones.

Manic gives attackers remote control of the device through WebRTC, allowing them to view the screen and interact with it using Android’s Accessibility features. It can hide its activity with black screens, fake screens or fake update messages, while also covering permission requests.

The July version goes a step further by removing itself from the device’s app launcher. This keeps it out of the normal app list and lets attackers activate it through its wrapper or a deep link.

For defenders, the combination here is complete in an uncomfortable way: credential theft, live screen monitoring, authentication interception, device takeover, and an exfiltration path that doesn’t require the infected device to have Internet access at all. Monitoring for unusual Accessibility service grants and unexpected Bluetooth or Wi-Fi Direct connections from phones that aren’t actively transferring files are the most practical detection starting points.

“Manic is an evolving Android fraud platform designed for Device Takeover (DTO), combining credential and authentication theft with live screen monitoring and remote control. Its targeting spans banks, payment and cryptocurrency services, eID applications, and messengers, with a strong focus on Ukraine.” concludes the report. “A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Android Malware)

Apple warned hundreds of users of mercenary spyware attacks

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance.

Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021.

“Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices.” reads the alert. “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”

That alone should reset the usual mental model. This isn’t about a suspicious app, a recycled phishing email, or the kind of opportunistic malware that lands wherever it can. Apple’s alerts concern highly targeted attacks against particular people, often because of their role, their work, or the people they know.

The people most likely to receive these notifications include journalists, activists, politicians, diplomats, lawyers, and others whose devices may hold valuable conversations, contacts, documents, or location data. That does not mean every recipient has been fully compromised, but it does mean Apple has observed enough to treat the risk as credible.

Apple has also changed how it delivers those alerts. A recipient may see a push notification directly on the iPhone lock screen and in Settings, receive an email from threat-notifications@email.apple.com, and find a warning banner after signing in to their Apple Account. The company says genuine notices will never ask users to click a link, open a file, install a profile, or provide a password or verification code by email or phone.

“Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” continues the report. “We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”

That lack of detail can frustrate recipients. They want to know who targeted them, how the device was approached, and whether the attacker got in. Apple can’t safely answer most of those questions in public, because publishing the detection logic would give spyware vendors a free quality-assurance report. Nobody needs to make Pegasus-style operators more efficient.

If you receive the warning, don’t panic and don’t start improvising. First, verify it by signing in directly at account.apple.com: a genuine Apple threat notification appears at the top of the page. Then preserve the device, avoid unnecessary resets or changes until you have spoken to someone qualified, and seek expert help, such as the Digital Security Helpline run by Access Now.

Apple recommends enabling Lockdown Mode, its high-security setting designed to reduce the attack surface available to sophisticated spyware. It also advises keeping devices updated, using a strong passcode with Touch ID or Face ID, turning on two-factor authentication, enabling Stolen Device Protection, using strong and unique passwords or passkeys, installing apps only through the App Store, and treating unexpected links or attachments as hostile until proven otherwise.

“Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.” states the alert. “As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”

The wider value of these alerts goes beyond the device in front of the recipient. Citizen Lab researcher John Scott-Railton told TechCrunch that notifications can reveal that an entire community is being targeted, because people who receive them often seek help and their cases lead investigators to others.

Most people will never receive one of these warnings. Apple says that plainly, and it is worth repeating because not every cybersecurity story needs to become a universal panic. But if your phone shows an Apple notice saying it detected a targeted mercenary spyware attack, assume it matters until an expert tells you otherwise.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App

Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem.

Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service and ended up mapping a sprawling criminal ecosystem built around a leaked Android RAT framework called Flying Eagle, 飞鹰. The investigation found 170 active servers, two Telegram channels distributing modified versions of the stolen codebase, and a likely successor platform already in version 2 development. Chinese state media had already warned citizens about the fake police app in June 2026. Nobody had yet traced what was behind it.

“Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase.” reads the report published by Hunt.io. “Flying Eagle combines APK generation and full-featured C2 device management in a single panel, with phishing overlays for financial, adult, and government service apps. The source code was stolen in early 2026, along with nearly 200 customer databases, leading to multiple modified variants circulating across criminal actors”

The leak turned a single commercial RAT into an open toolkit that anyone willing to pay 2,000 USDT for a “fixed” version, or nothing at all for the free Docker release dropped on Telegram in April, could deploy.

The framework is more capable than most MaaS offerings at this price point.

“The APK generation module accepts user-defined lured text, application names, icons, and C2 callback addresses, then builds a signed APK using one of two base templates.” continues the report. “Additional observed templates: Chinese adult streaming services, TikTok, financial applications, and landing pages for public welfare projects that send the number of visits and downloads back to the operator.”

To evade antivirus detection, the builder pads APKs with fake JSON configuration data and encrypts C2 callback URLs using AES-128-CBC with hardcoded cryptographic parameters.

The original class names in the source code tell you exactly what the tool does: RecordPayPassword, LiveKeysStrok, ScreenCaps, Webjector, CameraCap. At build time all of those get replaced with randomized 8-to-14 character strings, so static analysis hits a wall immediately.

Hunt.io identified the broader infrastructure through two independent fingerprints: the AdminPro title that briefly appears before operator branding loads, combined with a consistent HTTP 302 redirect behavior and Strict-Transport-Security header. A separate query for servers still running the default TLS certificate packaged with the Flying Eagle Docker deployment added another 12 unique servers. The pivot that connected the Docker version to a separate Windows XAMPP deployment was a misspelled environment variable, SECRIT_KEY, present in both codebases. Someone left a typo in the source, and it followed every fork.

The two Telegram channels operating around Flying Eagle have different roles. Yx科技 functions as sales and operational support: its first messages were step-by-step instructions for draining Alipay and WeChat accounts, referring to victims as “fish” and offering cash-out services at 20 to 50 percent transaction fees.

The SQLRCE0 Telegram channel, created in February 2026, was among the first to distribute Flying Eagle-related files. Researchers found that its posts indicated a leak of the RAT’s source code, including a chat screenshot between an unidentified actor and the malware developers known as “Flying Eagle Tech.”

“The chat showed a negotiation over access to 189 Feiying server and exfiltrated database, with the unknown party claiming to have compromised customer infrastructure.” continues the report. “SQLRCE0 used the ensuing messages to make multiple fixes to the leaked source code: domain connectivity, WebSocket stability, anti-uninstall features, and more all while assuring users with a money back guarantee that all backdoors had been removed from the code.”

Flying Eagle
Flying Eagle

A money-back guarantee on a backdoor-free criminal RAT. The market for this stuff is apparently competitive enough to require customer service.

On June 23, three weeks after Chinese state media published the public safety notice, SQLRCE0 introduced Night Dragon, 夜龙,as an independently developed successor. It’s not a reskin of Flying Eagle: it’s a separate build, currently in version 2 development as of July 12. Night Dragon adds a black-screen mode that shows a fake system update to hide operator activity, automatic icon hiding after installation, and single-click credential capture overlays for Alipay, WeChat, ICBC, Construction Bank, Agricultural Bank, and cryptocurrency wallets TokenPocket and imToken.

Hunt.io found one exposed Night Dragon panel showing 46 devices online with 29 actively connected, all geolocated in China. Whether those are real victims or test data is unverified. The operator account names translate to variants of “get rich,” which at least makes the intent clear.

“The device control interface provides full remote access including live screen viewing, SMS and photo gallery access, audio recording, camera capture, and file management. A phishing overlay system allows operators to deploy credential capture prompts for specific applications, with single-click shortcuts for Alipay, WeChat, and major Chinese banks including ICBC, Construction Bank, and Agricultural Bank, in addition to cryptocurrency wallets TokenPocket and imToken.” concludes the report. “Night Dragon represents an evolution beyond the variants of Flying Eagle. Where Yx Technology and SQLRCE0 both distributed modified versions of an existing codebase, this project appears to be an independent build, which is currently in active version 2 development as of July 12th. Its emergence just three weeks after the public safety notice suggests the demand for Chinese-language Android RAT tooling continues to drive criminal actors even as existing platforms are exposed.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Flying Eagle)

eSIM Plus and Nicegram Share Belarus-Linked Codebase, Analysis Finds

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services.

Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart both Android packages to see what the binaries themselves reveal, following OCCRP reporting that both apps are allegedly developed and controlled from Belarus. What they found in the code substantially corroborates that reporting.

“Most decisively, the eSIM Plus package is cryptographically signed by “Mobyrix, Minsk” (a Belarusian signature on an app marketed under the Lithuanian “Appvillis” brand), and it ships live integrations with two Russian services, Yandex AppMetrica (analytics) and Voximplant (call routing, via a .ru endpoint).” reads the report published by Mysterium VPN Research Team. “Nicegram shares the same “Appvillis” codebase and backend, though the specific Russian SDKs aren’t present in the Nicegram build we examined.”

eSIM Plus 4.4.26Nicegram 1.55.0
Signing certificateMobyrix, Minsk, Belarus (original key)Google Play re-sign (developer identity hidden)
Yandex AppMetricaYes — full SDK (yandex.net, appmetrica.io)No SDK present
VoximplantYes — full SDK (.ru balancer)No
LocationFine + coarse, tracking wiredFine + coarse + background
Other telephonyTwilioN/A
Analytics/CDPAppMetrica, Mixpanel, Segment, Customer.io, AppsFlyer, Facebook, Firebase, QonversionFirebase, Adjust, Qonversion, AdMob, AppsFlyer
Notable extrasPayment SDKsCrypto wallet (seed phrases), “God’s Eye” profiling

The signing certificate is the most decisive piece of evidence. It carries the Minsk postal code 220020. An app publicly presented under a Lithuanian-facing brand is cryptographically signed by a company in Belarus, not by inference, but directly from the certificate.

The Russian integrations in eSIM Plus are both confirmed and live. Yandex AppMetrica is fully wired in with around 2,900 code references, communicating with Yandex infrastructure at startup and reporting events to appmetrica.io. AppMetrica derives client IP server-side by design, and location tracking is enabled.

“eSIM Plus integrates the Voximplant calling SDK across a full call stack (VoximplantCallManager, VoximplantIncomingCallService, and related classes, ~1,700 references). It routes through balancer.root.voximplant.ru — a Russian (.ru) endpoint — under the account appvillis.n8.voximplant.com. (Confirmed.)” continues the report. “These are the two specific “leads to Russia” technical indicators named in the reporting, and both are genuinely present and wired to live production hosts.”

In other words, a user making a call through eSIM Plus is routing that call through Russian infrastructure, with no indication of this in the store listing.

The data collection surface on eSIM Plus is unusually wide even by the standards of free apps. It requests 35 permissions including fine and coarse location, contacts, camera, microphone, and telephony. On top of AppMetrica it carries Mixpanel, Segment, Customer.io, AppsFlyer, Facebook SDK, Firebase, and Qonversion, plus payment SDKs and a second telephony vendor. Nicegram’s data collection footprint is similarly broad — 73 declared permissions including background location, camera, and phone identity — and it additionally bundles a non-custodial crypto wallet with seed-phrase handling and a module the researchers call “God’s Eye” that profiles Telegram users’ activity patterns by sending channel and session data to Nicegram’s servers.

“the Nicegram 1.55.0 package we examined does not contain the Yandex AppMetrica SDK, does not contain Voximplant, and contains no .by endpoints or Mobyrix strings.”continues the report. “The only Russian-hosted domains reachable from Nicegram are static-maps.yandex.ru (an optional map-tile provider inherited from upstream Telegram) and coub.com (a media-embed service) — both benign, user-action-gated, and not telemetry channels. “

The Russian-SDK evidence is in eSIM Plus, not in this specific Nicegram build. The two apps corroborate the shared-developer claim; eSIM Plus is where the Belarusian signature and Russian data flows are direct and technical.

The structural problem this research exposes is straightforward. A user in the EU installs an app that presents as Lithuanian and unknowingly routes their identifiers, location, and voice calls through analytics and telephony services in Russia, built and signed by a company in Minsk. Nothing in the store listing told them this. The trust was assumed; the reality was only recoverable by pulling the binary apart. That gap — between what an app’s label says and what the package itself contains — is invisible at install time and only legible to someone willing to do a static teardown. Most users aren’t, and shouldn’t have to be.

“For users, the practical takeaway is that an app’s store-listed “publisher” and country can differ materially from who actually builds, signs, and receives data from the software — a gap that’s invisible in the store listing but legible in the package itself.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, eSIM Plus)

Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools

RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription

Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family.

It comes with documentation, tutorial videos, a referral discount program, and a bot that builds custom malicious apps on demand. No malware-writing skill required.

“Far from being just another basic piece of malware sold online, RedWing is a fully developed, commercial-grade MaaS product with seller documentation, videos, and a bot-driven subscription model that provides a low entry barrier for novice attackers.” reads the report published by Zimperium. “As a proof of this, the APK customization/obfuscation/creation can be fully implemented through telegram.”

Infection starts with a phishing link that opens a fake app store page. The dropper builder can mimic Google Play, the Samsung Galaxy Store, or Huawei’s AppGallery with fake ratings, reviews, and download counts.

“the C2 panel features a sophisticated ‘Onboarding Constructor‘. Within the ‘Stealer’ configuration module, operators can deploy a deceptive ‘WebView + Cards’ interface. This mechanism loads a benign-looking webpage in the background to establish legitimacy, while sequentially overlaying customized permission prompts (cards) from the bottom of the screen.” continues the report. “Through tailored social engineering lures, the malware coerces the user into granting critical system access, specifically targeting three core permissions: disabling Battery Optimization (to ensure uninterrupted background execution), setting the application as the Default SMS handler (crucial for intercepting 2FA codes), and access to Notifications.”

Once installed, the app walks the victim through permission screens one at a time, disable battery optimization, set the app as the default SMS handler, enable notifications, framed as routine setup steps.

With those permissions in place, RedWing has deep system access. It deploys fake login screens over real banking and crypto apps to steal credentials, reads incoming texts to capture one-time codes, and uses Android’s Accessibility Service to lift PINs, card numbers, and CVV values directly off the screen as they appear.

The malicious code also silently enables call forwarding using a hidden carrier code, 21, redirecting all incoming calls to an attacker-controlled number, which knocks out phone-based two-factor authentication and bank fraud-prevention calls in one move.

The researchers pointed out that the surveillance capabilities go further. RedWing can remotely activate a victim’s camera and microphone, recording audio through commands sent from the attacker’s server with configurable recording duration.

“The malware is capable of remotely activating the cameras and the microphone of an infected device (Fig. 12). This functionality is executed via specific commands. For instance, the <take_photo> command allows the attacker to remotely capture images using the device’s camera. Similarly, the <start_recording> command leverages the MediaRecorder API to capture ambient audio.” continues the report. “This audio recording process is managed entirely from the remote server, which allows the attacker to configure the exact duration of the recording, among other parameters.”

On top of that, operators get live screen streaming via VNC, a real-time keylogger, access to all files on the device, contact lists, call logs, and location tracking.

The targeting architecture reveals something telling about how RedWing is built. The apps it monitors through Accessibility are baked into each compiled copy, which points to a fresh APK being generated server-side each time a buyer specifies their targets. The overlay targets, by contrast, can be updated from the control panel at any time without distributing a new app.

Zimperium identified 82 targeted institutions across multiple sectors, with a heavy focus on Russian financial firms, one sample used a fake RuStore page, though the list can shift at any time from the operator’s dashboard.

RedWing doesn’t need any Android vulnerability to work. It relies entirely on the user installing an app from outside an official store and approving its permission requests. The first line of defense is what happens at install time: don’t install apps from links sent by text or messaging apps, don’t grant Accessibility or default-SMS access to apps with no clear reason to need them, and treat any app that hides its icon after installation as a red flag. On managed devices, sideloading can be blocked centrally and suspicious permission requests flagged automatically.

RedWing can also transform infected Android devices into a botnet capable of launching coordinated DDoS attacks. Through its control panel, attackers can command multiple compromised phones at once to send traffic floods against a target website or server, disrupting its availability and adding another capability beyond spying and data theft.

Because operators can reskin the app and swap its targets from the control panel, the app name is a poor indicator, behavior is what to watch for.

“The rapid rise of Malware-as-a-Service (MaaS) operations like RedWing shows how easily attackers can weaponize legitimate Android components to achieve full device compromise. Unlike older banking trojans that rely solely on overlays, RedWing integrates custom droppers, live screen streaming, and abuse of the SMS handler role and Accessibility to exfiltrate data and impersonate legitimate apps in real time.” concludes the report. “This blend of social engineering and hijacking the incoming calls makes this deep-system control especially dangerous in BYOD and consumer-facing environments where app-store trust is assumed.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Malware)

Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds

A former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab.

The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly infected with NSO Group‘s Pegasus spyware while serving on the very committee tasked with investigating Pegasus abuses across the EU. The PEGA Committee ran from March 2022 to July 2023. Kouloglou was on it the entire time.

“We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Europe.” reads the Citizen Lab report. “Through forensic analysis of his device, we found that the attackers could have had access to confidential documents and committee deliberations.”

The infections happened on October 21, 2022, and again on March 6 and 7, 2023, both during periods of intense PEGA activity. The first infection came ten days before a planned committee visit to Greece and Cyprus, and while drafts of the first PEGA report were circulating among members. The second hit while the committee was deep in the final drafting process, two months before the report’s adoption in May 2023.

The delivery mechanism for the first infection was PWNYOURHOME, a zero-click exploit targeting Apple’s HomeKit system.

“On 2022-10-21 10:16, there was a lookup for a HomeKit email address rauharepo888 [@]gmail.com. Two minutes later, a Pegasus process used mobile data. We assess that the phone was hacked with the PWNYOURHOME zero-click exploit at this point.” continues the report. “PWNYOURHOME appeared to first involve the attacker sending a specially crafted NSKeyedArchive that landed in HomeKit, followed by malicious content that landed in MessagesBlastDoorService.”

the researchers noted. No interaction required from Kouloglou. His device was running iOS 15.5 on both infection dates — a version Apple had already moved past. He also received three Apple threat notifications about mercenary spyware targeting, in March 2023, August 2023, and April 2024. He told the Citizen Lab he didn’t recall seeing any of them.

The timing of the first infection adds another layer. On October 21, 2022, Kouloglou was in a Greek hospital for elective surgery. He was visited that day by investigative journalist Thanasis Koukakis, who had himself been confirmed as a Predator spyware target and had testified before the PEGA Committee the month before. If Pegasus captured conversations in that hospital room, Greek law covering confidentiality of health data may have been violated.

Citizen Lab says it is highly confident that former MEP Stelios Kouloglou was infected with Pegasus, but cannot identify the NSO’s customer behind the attack. Researchers found no evidence linking the operation to the Greek government, which has instead been associated with Predator spyware. Technical evidence suggests the same Pegasus operator also targeted Russian and Belarusian journalists and activists in Europe. The infections occurred in both Greece and Belgium, indicating the spyware operator likely held a license allowing surveillance across multiple EU countries.

“We further note that infections appear to have been present on his phone in at least two European jurisdictions (We further note that infections appear to have been present on his phone in at least two European jurisdictions (Greece and Belgium).” continues Citizen Lab. “Based on what we know of NSO Group’s licensing, this would likely indicate that the customer had a license that enabled infections in multiple EU jurisdictions, narrowing the list of potential Pegasus operators that could be responsible for this case.”

The same HomeKit email address used against Kouloglou in 2022 appeared in a prior Citizen Lab investigation into Pegasus infections of Russian and Belarusian-speaking journalists and activists living in Europe.

This is the first confirmed case of a PEGA Committee member being hacked with Pegasus while the committee was in session. It’s not the first MEP targeted with spyware, Catalan MEPs were hit with Pegasus as far back as 2019, and French MEP Nathalie Loiseau confirmed she was targeted in early 2024. The Citizen Lab is now calling on the European Parliament to investigate the full scope of spyware targeting during the PEGA proceedings, and urging DG ITEC, which already offers optional spyware screening for MEPs, to significantly increase screening rates and publish yearly statistics.

The committee spent more than a year investigating who was spying on Europeans. Someone was apparently taking notes the whole time.

“Whichever entity is responsible for the hacking, the infection could have exposed strictly confidential exchanges among PEGA Committee members and their staff, and other sensitive and confidential parliamentary proceedings, including to parties under investigation by the Committee itself.” concludes the report. “The finding that a PEGA Committee member was targeted with Pegasus spyware during the Committee’s work highlights the serious threat that mercenary spyware poses to the integrity of democratic processes. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pegasus spyware)

WhatsApp Usernames Are Coming. You Can Reserve Yours Right Now

WhatsApp will introduce usernames later this year, letting its 3 billion users connect without sharing phone numbers.

WhatsApp has over three billion users, and it’s finally letting them talk to each other without exchanging phone numbers. The company announced this week that usernames are coming later this year, and reservations are open now.

The problem they’re solving is real. Your phone number is tied to your bank, your doctor, your family. Handing it to a stranger at a networking event, or to twenty parents you’ve never met in a school group chat, has always felt like more than it should be. A username fixes that without requiring you to create a separate account anywhere.

When the feature is available, users can set a username and share that instead of their number. When you message someone for the first time, they won’t see your phone number at all, as long as you’ve enabled your username. That’s a meaningful change for anyone who currently has to choose between joining a group and keeping their number private.

There’s no public directory and no suggestion algorithm. Someone has to know your exact username to reach you, which keeps the search-and-spam problem that plagues other platforms from becoming WhatsApp’s problem too. For an extra layer of control, there’s an optional “username key,” a secondary credential someone needs before they can message you at all.

Three billion users means an enormous amount of name overlap. WhatsApp is opening reservations now, before the feature goes live, so people have a real shot at the handle they actually want rather than finding it already taken on launch day.

You reserve yours through Settings > Account > Username on the latest version of the app. It takes about ten seconds.

Creators, businesses, and organizations can claim their existing Instagram or Facebook username on WhatsApp to keep things consistent across platforms. WhatsApp built a username generator for everyone else who can’t think of anything and doesn’t want to spend forty-five minutes staring at their phone. (We’ve all been there.)

“For most people, choosing a WhatsApp username should be something unique that only people you want to contact you will know. If you need help picking one, we have a username generator to make one work just for you.” reads the announcement. “We also know that some people like creators, small businesses, and organizations may want to maintain a consistent presence online. For them, we reserved an option to claim their existing Instagram or Facebook username on WhatsApp.”

WhatsApp calls this feature “our latest step to make WhatsApp even more private”. That framing matters because the app built its reputation on end-to-end encryption, and this extends the privacy promise to the layer before the conversation even starts: who knows how to reach you.

“Usernames are our latest step to make WhatsApp even more private. There’s no directory to browse and no suggestions – people will need to know your exact username to contact you for the first time.” continues the announcement. “To help control who can reach you on WhatsApp with your username, we’ve built an optional username key that others will need to know to message you.”

The original post also frames the core need plainly: “a phone number is personal and it’s tied to so many parts of your life”. That’s the exact tension usernames are designed to dissolve, whether you’re joining a neighborhood group, talking to a new client, or just not ready to hand your digits to someone you met once.

WhatsApp pointed out usernames are private by design: there’s no public directory or search suggestions. People can contact you only if they already know your username.

The rollout will happen gradually over the coming months, with in-app notifications when usernames become available in your region. If you want a specific handle, reserve it now. By the time this goes live, the obvious ones will already be gone.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, privacy)

Activist Phone Hacked With Cellebrite After Russia Contract Cancellation

Russian authorities used Cellebrite tools to unlock an activist’s iPhone and analyze private data despite canceled support, raising abuse concerns.

On May 31, 2021, Russian security services pulled opposition activist Andrey Pivovarov off a flight at St. Petersburg airport and confiscated his iPhone 12 and MacBook. He never consented to a search and never gave up his passwords. Three weeks later, on June 17, while his devices sat in custody, Russian authorities used Cellebrite ‘s forensic tools to break into his phone. Cellebrite had announced it was stopping sales to Russia three months earlier.

The Citizen Lab published its findings on June 25, 2026. What makes this case unusual is that the evidence comes from two independent sources that line up exactly.

“Our analysis found traces of the use of Cellebrite’s forensic tools with high confidence on Pivovarov’s iPhone 12 on or around June 17, 2021, during a period when the device was in the custody of the Russian authorities.” reads the report published by Citizen Lab. “Our forensic analysis of MobileLockdown records from Pivovarov’s iPhone show USB connections to a device with a Host ID on June 17, 2021 that we previously attributed to Cellebrite.”

The second source is Russia’s own paperwork. Pivovarov received a prosecution document, Forensic Expert Report No. 1269-17, prepared by the Interior Ministry’s forensic center, and he gave a copy to the Citizen Lab. It names Cellebrite UFED Physical Analyzer and UFED 4PC by product name.

The investigators didn’t just extract data. They searched it.

“The authorities documented gathering extensive information from the device, including data from apps like WhatsApp, Telegram, and Viber.” continues the report.

The MVD report shows searches for “Open Russia Civic Movement” and for named individuals including Mikhail Khodorkovsky, who founded Open Russia, human rights lawyer Anastasiya Burakova, and Pivovarov’s partner Tatiana Usmanova. This was a political map-building exercise disguised as a criminal investigation.

The MacBook resisted. Russia’s own report documents a failed extraction attempt, blocked by disk encryption, and Citizen Lab forensics found matching failed login attempts on June 17, confirming the authorities never had the password. Pivovarov was sentenced to four years in July 2022 on charges of running an “undesirable” organization — a label Russia applied to Open Russia, and one the European Court of Human Rights later found incompatible with the European Convention on Human Rights. He was freed in August 2024 in a prisoner exchange.

The timing raises a question Cellebrite can’t easily answer. The company cancelled its Russian contracts in March 2021, which cut off future updates but left existing hardware running.

The Russian and Belarusian authorities would cease to receive updates for their Cellebrite devices, but evidence demonstrates that more than a year later, Russian autorities were still using the tool to hack political detainees’ cellphones.

“Our forensic findings confirm the reports that Russian authorities developed a range of methods to continue leveraging Cellebrite in political prosecutions (as well as other device hacking tools) despite the contract cancellation. The historic architecture of Cellebrite forensic systems means that much of the functionality in the UFED product has continued to operate long after updates cease.” continues the report. “Furthermore, Cellebrite systems have historically featured an offline mode. Consequently, the way Cellebrite’s technology was designed appeared to make it difficult for the company to meaningfully cut off problematic customers.”

Cellebrite told the Citizen Lab that any use of its legacy hardware after March 2021 is “entirely unauthorized” and that the hardware runs without its support or consent. That’s legally accurate and operationally irrelevant: the tool worked, the phone was open, and the extraction happened.

There’s an additional thread worth following. The names pulled from Pivovarov’s phone later appeared as targets in a COLDRIVER phishing campaign, the FSB-linked operation that went after Russian opposition figures abroad. Burakova was targeted but didn’t open the attachment. The Citizen Lab doesn’t claim a direct causal link, but the mechanism is straightforward: extract one activist’s contact list and you have a ready-made target list for the next operation.

Russia now joins Serbia, Kenya, and Jordan on the Citizen Lab’s list of Cellebrite abuse cases backed by hard forensic evidence. Cellebrite says it’s moving to subscription licenses that stop working when they expire, which would prevent the installed-base problem from recurring.

The company’s track record, selling to repressive governments, cancelling contracts only after third-party exposure, and reacting selectivelym makes that commitment worth watching rather than simply trusting.

“Cellebrite’s record suggests it is comfortable pursuing contracts with governments that are likely to use its technology to commit human rights abuses. Cellebrite previously sold to autocratic and repressive countries including RussiaBelarusChinaJordanKenyaMyanmarSerbia, and Botswana, among others.” concludes the report. “There is also a growing list of forensically-documented cases in which Cellebrite technology was used for political repression, from Serbia and Kenya to Jordan and now Russia, and where the company has shown a mixed record of contract cancellations.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, mobile)

❌