Tech News
← Home  ·  All topics

Android Malware

7 GoKawiil briefs on this topic

RatHat Android malware uses AI agent to hijack devices via fake Chrome app

Security firm Zimperium has identified RatHat, a new Android malware strain that tricks users into installing a fake app resembling Google Chrome through a spoofed Play Store page. Once granted accessibility permissions, it silently enables developer-level ADB Shell access, deploys an AI-driven agent to run system commands, and funnels stolen data to remote servers. Researchers have already found 162 infected apps tied to roughly a dozen attacker-controlled servers, with China-linked actors primarily targeting payment apps like WeChat Pay and Alipay.

RatHat Android trojan uses AI to autonomously navigate infected devices, Zimperium finds

Zimperium zLabs identified a new Android malware family, RatHat, spread via malvertising, SMS and phishing sites offering APK downloads outside Google Play. It abuses Accessibility permissions and enables Developer Options and Wireless Debugging to gain shell-level control, installing companion agents that maintain persistence, log keystrokes, and steal banking or crypto credentials through fake overlays. Researchers link the operation to Chinese-speaking actors based on Chinese-language prompts found in its AI automation engine.

Mantax Otax Android Malware Blends Ransomware and Spyware to Extort Indonesian Victims

Security firm Zimperium has identified a new Android malware called Mantax Otax that combines file encryption with data theft, distributed via malicious APKs outside Google Play through phishing lures aimed at Indonesian users. Once installed, it abuses Accessibility permissions to harvest device data, report to a GitHub-hosted command server, and on older Android versions (9 and below) encrypts files, replaces images with ransom notes, and opens a Firebase-hosted chat to negotiate payment. Researchers exploited a misconfigured Firebase server to expose the attackers' actual conversations with victims.

BadBox 2.0 Botnet Malware Found Infecting Android-Based Car Infotainment Units

Researchers have identified that operators behind the BadBox click-fraud botnet are now targeting Android-powered vehicle head units, exploiting built-in update mechanisms to push malicious software onto the devices. This marks an expansion of the botnet's reach beyond streaming boxes and smart TVs into automotive infotainment systems.

ToxicPanda Android Trojan Adds Features Targeting Enterprise Systems

Security researchers report that ToxicPanda, an Android banking trojan, has been updated with new capabilities that extend its reach beyond individual financial apps. The revised malware now poses risks to broader enterprise environments, not just personal banking credentials.

Kaspersky finds malware built into Android car head unit firmware updaters

Kaspersky researchers discovered a new Android malware strain in June 2026 that spreads through the built-in update mechanisms of Android-based automotive head units, marking the first documented infection chain targeting this device category. The app installs silently with no interface, functioning as a multi-stage downloader designed for ad fraud and building a proxy botnet. Kaspersky attributes the campaign with high confidence to MoYu Group, an actor tied to the previously known BADBOX botnet.

ToxicPanda banking trojan updated to abuse VPN permissions and block Google Play

Zimperium researchers found a new version of the ToxicPanda Android malware that requests VPN service permissions to intercept and control device network traffic, allowing it to cut off communication with Google Play and Play Protect. The updated trojan, spread via Amazon AWS-hosted buckets, now supports 167 remote commands and phishing overlays for 349 banking, crypto, and e-wallet apps across 16 countries, plus a separate module that harvests PINs from 140 financial apps.