CuraSec

tag: Android-Malware · 6 items

  • Engineer — Skip
  • SOC/IR — Learn: StreamRat demonstrates a malvertising delivery chain for Android banking trojans capable of near-complete device takeover; worth noting the ad-platform distribution vector for mobile threat modeling, though no IOCs or ATT&CK mappings are available to act on today.
  • Leader — Skip
  • Engineer — Skip
  • SOC/IR — Learn: The VPN-permission-as-blocker technique is a noteworthy evasion TTP for mobile threat awareness, but the summary provides no IOCs or detection signatures to act on; file for context when tuning mobile EDR or MAM policies.
  • Leader — Skip
2026-08-22 · The Hacker News · source ↗ #android-malware#supply-chain#botnet
  • Engineer — Skip
  • SOC/IR — Learn: The updater-as-delivery-channel technique on Android-based embedded devices is a noteworthy TTP, and the proxy botnet component could eventually surface in network telemetry — but no IOCs or ATT&CK mappings are provided, leaving no concrete detection action available today.
  • Leader — Skip
2026-08-20 · The Hacker News · source ↗ #android-malware#mobile-banking#fraud
  • Engineer — Learn: No infrastructure or cloud exposure here; this is a mobile banking trojan. Worth understanding the PIN-harvesting technique if your org develops mobile banking apps, but no patch or configuration action required.
  • SOC/IR — Plan: No IOCs published in this item, but the expanded 140+ targeted app list and new remote-command capability warrant building or tuning mobile threat detections; review Zimperium’s full report for indicators to add to mobile MDM alerting.
  • Leader — Learn: Relevant if your org operates a banking or crypto app; file as emerging mobile fraud risk for the next risk-register review, but no immediate board-level action indicated without corroborating incident data.
  • Engineer — Skip
  • SOC/IR — Learn: The P2P relay exfiltration method — routing data through nearby compromised devices — is a novel evasion technique worth understanding, but no IOCs or enterprise-targeting details are published yet to build detections against.
  • Leader — Skip
2026-08-13 · BleepingComputer · source ↗ #android-malware#nfc-relay#financial-fraud
  • Engineer — Skip
  • SOC/IR — Learn: WindRelay/SpyNote combo represents a maturing NFC relay technique worth tracking for mobile threat awareness, but no enterprise detection surface or IOCs are provided to act on.
  • Leader — Skip