Security firm Zimperium has identified RatHat, a new Android malware strain that tricks users into installing a fake app resembling Google Chrome through a spoofed Play Store page. Once granted accessibility permissions, it silently enables developer-level ADB Shell access, deploys an AI-driven agent to run system commands, and funnels stolen data to remote servers. Researchers have already found 162 infected apps tied to roughly a dozen attacker-controlled servers, with China-linked actors primarily targeting payment apps like WeChat Pay and Alipay.
cnet.com
· 2026-09-20
Zimperium zLabs identified a new Android malware family, RatHat, spread via malvertising, SMS and phishing sites offering APK downloads outside Google Play. It abuses Accessibility permissions and enables Developer Options and Wireless Debugging to gain shell-level control, installing companion agents that maintain persistence, log keystrokes, and steal banking or crypto credentials through fake overlays. Researchers link the operation to Chinese-speaking actors based on Chinese-language prompts found in its AI automation engine.
bleepingcomputer.com
· 2026-09-17
Security firm Zimperium has identified a new Android malware called Mantax Otax that combines file encryption with data theft, distributed via malicious APKs outside Google Play through phishing lures aimed at Indonesian users. Once installed, it abuses Accessibility permissions to harvest device data, report to a GitHub-hosted command server, and on older Android versions (9 and below) encrypts files, replaces images with ransom notes, and opens a Firebase-hosted chat to negotiate payment. Researchers exploited a misconfigured Firebase server to expose the attackers' actual conversations with victims.
bleepingcomputer.com
· 2026-09-10
Researchers have identified that operators behind the BadBox click-fraud botnet are now targeting Android-powered vehicle head units, exploiting built-in update mechanisms to push malicious software onto the devices. This marks an expansion of the botnet's reach beyond streaming boxes and smart TVs into automotive infotainment systems.
darkreading.com
· 2026-08-26
Security researchers report that ToxicPanda, an Android banking trojan, has been updated with new capabilities that extend its reach beyond individual financial apps. The revised malware now poses risks to broader enterprise environments, not just personal banking credentials.
darkreading.com
· 2026-08-24
Kaspersky researchers discovered a new Android malware strain in June 2026 that spreads through the built-in update mechanisms of Android-based automotive head units, marking the first documented infection chain targeting this device category. The app installs silently with no interface, functioning as a multi-stage downloader designed for ad fraud and building a proxy botnet. Kaspersky attributes the campaign with high confidence to MoYu Group, an actor tied to the previously known BADBOX botnet.
securelist.com
· 2026-08-23
Zimperium researchers found a new version of the ToxicPanda Android malware that requests VPN service permissions to intercept and control device network traffic, allowing it to cut off communication with Google Play and Play Protect. The updated trojan, spread via Amazon AWS-hosted buckets, now supports 167 remote commands and phishing overlays for 349 banking, crypto, and e-wallet apps across 16 countries, plus a separate module that harvests PINs from 140 financial apps.
bleepingcomputer.com
· 2026-08-23