David Blanc

@speekha.bsky.social

Mobile Security Expert at BPCE-SI. Former #Android lead developer. Definite Kotlin lover. Author of HttpMocker.

One thought when I see that practically all malwares (especially the ones targeting banking or financial apps) use the same overlay and accessibility service tricks : not all apps implement biometry properly, but at least, malwares can't steal your PIN or passwords if you never type them.

New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones

New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones

A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet connection of its own, it can quietly borrow one from another infected device nearby. The malware was identified by ThreatFabric’s Mobile Threat Intelligence team, which describes Manic as sitting at the intersection of Android banking trojans and mobile spyware. Rather than focusing on a single scam, Manic gives its operators a complete fraud toolkit : it can read a victim’s PIN, watch their screen live, hijack banking sessions, and pull files, messages, and location data off the device. ThreatFabric traced Manic’s infrastructure back to February 2026, with development accelerating through the spring and a more advanced version emerging by July featuring stronger anti-analysis defenses and in-memory code loading. The malware currently monitors 169 apps, spanning banks, government identity portals, payment services, cryptocurrency wallets and exchanges, authenticator apps, and messaging platforms. Ukraine is clearly the priority, covering national banks and eID services, but the target list extends into Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, along with global fintech and crypto platforms That mix tells its own story. Financial institutions and crypto wallets point to straightforward theft, while the inclusion of government identity apps and both commercial and military-oriented messengers suggests the operators also want insight into a victim’s communications, not just their bank balance. Most banking trojans steal credentials by throwing up a convincing fake login screen over the real app, a technique known as an overlay attack. Manic largely skips that step. Instead, once it has Accessibility and notification permissions, it places a transparent layer only over the numeric keypad of a genuine banking app, quietly recording where the victim taps. It then replays those exact taps back to the real app through Android’s Accessibility service, so the transaction goes through normally while the PIN is logged in the background. The malware applies a similar trick to the lock screen itself, attempting to capture and later reuse the device’s unlock code or pattern. Combined with SMS and notification interception, and live WebRTC screen-sharing sessions that let an operator watch and interact with the phone in real time, Manic effectively gives attackers hands-on remote control of a victim’s device. The most distinctive part of Manic’s design is how it moves stolen data off the device. When an infected phone cannot reach its command-and-control server directly, it does not give up. Manic MITRE ATT&CK Matrix (Image Source: ThreatFabric) Instead, it encrypts the collected data, stores it locally, and searches for another infected phone nearby using Wi-Fi Direct, Bluetooth, or BLE that does have internet access. That second device then forwards the package onward, effectively turning ordinary infected phones into an unwitting mesh network for data exfiltration. This peer-relay approach means that cutting off a single phone’s internet connection is not enough to stop data from leaking out, as long as another compromised device is within radio range. Manic’s blend of stealthy PIN capture, deep device takeover, and a self-healing exfiltration network makes it harder to detect and harder to contain than a typical banking trojan. Device Takeover Fraud Path (Image Source: ThreatFabric) ThreatFabric’s continued tracking of the campaign, alongside similar 2026 discoveries like the WindRelay NFC relay malware and the human-mimicking Herodotus trojan, points to a broader trend of Android threats layering multiple fraud techniques into a single platform. Security teams and everyday users alike are advised to avoid sideloading APKs from unofficial sources, scrutinize any app requesting Accessibility permissions, and keep Google Play Protect active, since Manic and similar families rely heavily on these permissions to operate Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones appeared first on Cyber Security News .

cybersecuritynews.com

ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones

ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones

A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted screens, and take deeper control of infected phones through a feature intended for developers. ToxicPanda 2.0 arrives with a far broader set of targets and remote commands than earlier versions. It is delivered through malicious files hosted in Amazon AWS buckets, then uses a fake installation flow to persuade victims to approve sensitive Android permissions. Researchers at Zimperium identified the updated malware and said it has 167 remote commands. The campaign can target more than 140 banking and cryptocurrency apps for PIN theft, while its fake login overlays now cover 349 financial institutions across 16 countries. The scale matters because the attack does not rely on one stolen password alone. Once installed, ToxicPanda can monitor apps, collect on-screen information, capture touch input, display deceptive pages, and help attackers keep access to the device. Earlier ToxicPanda activity had already infected more than 4,500 devices, largely in Portugal and Spain. Zimperium said in a report shared with Cyber Security News (CSN) that the new variant also uses Android Wireless Debugging to obtain shell-level access. That technique gives criminals a route to run commands and weaken normal Android protections without needing physical access to the phone. ToxicPanda Android Malware The infection begins with a dropper app that displays a false installation interface and asks for VPN-related permission. This may let the malware interfere with connections to Google Play and Google Play Services before it decrypts and installs its concealed payload. Dropper requesting VPN permission to the victim before payload installation (Source – Zimperium) Accessibility permissions are central to the operation. They allow ToxicPanda to inspect what appears on screen and interact with the interface, a pattern also seen in  Android banking trojan attacks  that use fake sign-in windows to capture account details. Malware installs the payload and requests Accessibility Service permissions (Source – Zimperium) After installation, ToxicPanda inventories the applications on the device and sends their package names and icons to its command-and-control server. When a victim opens a selected financial app, the server can return a matching HTML overlay that resembles the genuine login or payment screen. The malware can also place a transparent layer over a banking keypad to record the victim’s taps. Its  <replacePinTargets>  command lets operators update the list of apps and keywords used for PIN collection, allowing campaigns to change targets without issuing a new malicious app. Malware overlays on top of the victim’s screen (Source – Zimperium) Its Wireless Debugging abuse is especially concerning. ToxicPanda uses automated screen interactions to enable Developer Options, turn on Wireless Debugging, trigger pairing, and collect the temporary six-digit pairing code. It then pairs with the local ADB service at  127.0.0.1  and gains shell user capabilities. With shell-level access, the malware can attempt to grant itself permissions, bypass background restrictions, enable components quietly, and improve its persistence on the device. This expands the threat beyond a conventional credential-stealing app. Overlays Hide Persistent Control ToxicPanda can also steal device-unlock PINs, passwords, and patterns using a fake Android lock screen. The overlay is designed to resemble the legitimate screen, turning a routine unlock attempt into another credential collection opportunity. In some samples, the attackers use a fake full-screen system update to conceal malicious activity. This social-engineering method can keep users occupied while the malware changes settings or waits for sensitive information, echoing tactics described in  fake Google Play updates  used by other Android banking threats. Malware overlay used to steal password of the victim (Source – Zimperium) The updated command set includes options to request Device Administrator privileges and force-reset the phone’s lock-screen password. Another command can load an attacker-controlled web page in a full-screen WebView, giving criminals another way to present phishing content or misleading prompts. ToxicPanda also attempts to survive Android power-management controls. It identifies the device manufacturer and uses Accessibility Services to navigate vendor-specific auto-start and battery settings, aiming to prevent the operating system from stopping its background processes. Similar abuse of accessibility-driven device control has become a recurring feature of  modern Android banking malware . Users should avoid installing APK files from unsolicited links or unofficial download pages. They should treat unexpected requests for Accessibility Service, Device Administrator, VPN, Developer Options, or Wireless Debugging permissions as a warning sign, especially when the requesting app is not clearly trusted. Organizations should watch for unusual Accessibility activity, automated changes to developer settings, suspicious overlay behavior, and unexpected ADB pairing events. Removing unrecognized apps promptly and reviewing enabled accessibility services can help limit exposure before criminals can establish persistent control. Indocators of compromise (IoCs):- Type Indicator Description IP address 127.0.0.1 Local ADB daemon address used during ToxicPanda’s Wireless Debugging pairing process.  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones appeared first on Cyber Security News .

cybersecuritynews.com

Everyone on the internet needs to know three things: 1: Assume anything online can become public. 2: People are easier to hack than apps. 3: Your digital life is only as secure as your weakest account. What did we miss?

Can't believe my proposal got accepted! I will be presenting my talk about AN0M at masCon, as part of next.app devcon 2026 in Berlin. It's time to think about compressing the content to fit it in the 20 min slot... www.nextappcon.com/agenda

You have been accepted as a speaker for this event!
OWASP® Foundation@owasp.org · 3mo ago

Join OWASP + next.app in Berlin (Oct 7–9, 2026) for 3 days focused on mobile app security We’re looking for talks on: 📱 iOS/Android security 🤖 AI in mobile apps ⚙️ DevSecOps & testing 🛡️ OWASP MAS Submit your talk👇 sessionize.com/nexta... Learn more: www.nextappcon.com/m...

Incredible. When E—n M—k & his crew obliterated USAID in a weekend, they deleted a vast trove of publicly-funded knowledge: the Development Experience Clearinghouse. A Canadian high school student (!) happened to have downloaded the entire thing for a project. AidData has now posted it for all.

Before reimagining development data, remember what we’ve learned

Why we’re publishing a free, searchable, and ungated archive featuring a quarter-century of USAID evaluation reports.

aiddata.org

I don’t know if I ever shared this here, but I created a platform to help Android devs overcome the 12 testers for 14 days Google Play requirement to unlock production. Completely free. Android devs helping each other. You test apps, and you get credits to list yours for test 👇 get12testers.com

Get12Testers — Get 12 testers for 14 days continuously and for free

Meet Google Play testing requirement. Get your app tested by 12 testers for 14 days continuously.

get12testers.com

Something big might happen to the Kotlin Multiplatform Ecosystem 👀 We were never too happy about how Kotlin publishes and resolves KMP libraries. It takes up significantly more space than it has to, produces a ton of artifacts and Maven modules, and is just... complex!

Your iphone Will Alert You in Real Time if You Are Falling Victim to a Scam

Your iphone Will Alert You in Real Time if You Are Falling Victim to a Scam

Apple is taking a major step toward combating social engineering attacks with a new feature in iOS 27 that can warn users in real time if they are likely being targeted by a scam. The new framework, called Trust Insights, is designed to detect suspicious behavioral patterns across user interactions, including apps, calls, messages, and other activities. Unlike traditional security tools that scan for malicious files or links, Trust Insights focuses on identifying behavioral signals indicating that a user may be manipulated into taking risky actions. Apple highlights that modern scams often rely on psychological tactics rather than technical exploits, making them harder to detect using conventional methods. The Trust Insights framework runs on-device primarily and analyzes factors such as interaction timing, contextual behavior, and basic sensor data. iPhone Scam Alerts This allows the system to detect if a user is being guided or “coached” through actions commonly associated with scams, such as transferring money, sharing sensitive information, or changing account settings. According to 9to5Mac , Trust Insights rates suspicious activity as medium or high risk, enabling apps to warn users, delay actions, or request additional verification before proceeding. This approach aims to disrupt ongoing scams without significantly disrupting legitimate user activity. Apple emphasized privacy as a core component of the framework. Trust Insights does not inspect the content of Messages, Mail, Photos, or other personal data. Instead, it processes behavioral data locally on the device and discards raw data immediately after analysis. Only a single risk signal is transmitted to Apple’s servers, where it may be combined with account-level indicators such as unusual login behavior to produce a final assessment. The framework supports five key operation categories where scams are most likely to occur: Payments: Financial transactions and in-app purchases. Account Changes: Credential and security setting updates. Resource Usage: High-cost actions, such as AI processing. Communication: Sending messages or signing documents. Other: Any remaining sensitive activities. Apple has also built safeguards into the system to prevent attackers from disabling protections. While users can turn off Trust Insights in device settings, Apple notes there may be a cooldown period before changes take effect. This is intended to protect users who may have been coerced into disabling security features. Developers are encouraged to integrate Trust Insights into their apps and provide feedback to Apple at the WWDC26 Conference. This includes reporting how the framework impacts user transactions and flagging confirmed fraud cases to improve detection accuracy over time. The introduction of Trust Insights comes amid a sharp rise in social engineering attacks, including tech support scams, impersonation fraud, and AI-driven deepfake schemes. By focusing on real-time behavioral analysis and privacy-preserving machine learning, Apple aims to provide a proactive defense layer against evolving threats. With iOS 27, iPhone users may soon receive timely warnings to help them avoid scams, marking a shift from reactive security to real-time intervention.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now . The post Your iphone Will Alert You in Real Time if You Are Falling Victim to a Scam appeared first on Cyber Security News .

cybersecuritynews.com

New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise

New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise

A novel BootROM vulnerability, dubbed usbliter8, affects Apple devices powered by A12, S4/S5, and A13 SoCs. The exploit chains a hardware-level bug in the Synopsys DWC2 USB controller with a firmware configuration flaw, enabling full application processor boot-chain compromise with no software patch possible due to the immutable nature of BootROM code. According to Paradigm Shift researchers, the vulnerability originates in how the DWC2 USB controller handles consecutive USB Setup packets. The controller stores up to three Setup packets in memory before resetting the DMA base address (stored in the DOEPDMA register) to its starting position, functioning like a ring buffer. The critical flaw: after each write, the controller increments DOEPDMA by the size of data written, but the reset operation always decrements it by a fixed 24 bytes. Since the controller also accepts smaller packets stored in 4-byte chunks, the pointer arithmetic breaks down. The mismatch between the variable increment and the fixed decrement produces a buffer underflow primitive in 12-byte steps, allowing controlled writes to memory regions outside the intended buffer. On A12 and A13, the USB DART (Device Address Resolution Table) is configured in bypass mode within SecureROM, meaning there is no IOMMU barrier to stop the DMA from overwriting arbitrary SRAM data. A14 and later generations configure DART correctly, rendering the vulnerability unexploitable on newer hardware. Exploitation Differences: A12 vs. A13 On A12 and S4/S5, exploitation is relatively straightforward. The DMA buffer sits adjacent to the USB task’s stack on the heap. Attackers corrupt a saved Link Register (LR), gaining PC control during a scheduler context switch. A compact ROP chain then redirects DMA writes into the boot trampoline normally non-writable from EL0 before jumping into SecureROM’s EL1 transition routine to execute attacker shellcode with full privileges. A13 introduces Pointer Authentication (PAC), complicating direct LR corruption. Researchers developed a multi-step technique involving controlled overwrites of DART heap metadata, neutralizing heap checksum protections, and suppressing reboots on panic by overwriting a global panic counter with a 0xF write primitive. Execution is ultimately rerouted through a gadget that loads a function pointer from attacker-controlled memory, bypassing PAC because only the IB key is enabled in the firmware an oversight that proves fatal. With EL1 code execution achieved, the exploit injects a custom USB request handler into unused boot trampoline space, patches the USB serial number to include the “PWND” identifier, and restores corrupted heap allocations to maintain device stability. On A13, the extent of memory corruption requires a full SecureROM restart researchers copy the ROM into SRAM, remap it via custom MMU translation tables, and hook ROM PTE generation to maintain address space consistency through the restart. The custom handler supports two privileged operations: SoC demotion (temporarily lowering production mode) and unsigned iBoot booting (bypassing all signature verification on raw iBoot images), effectively nullifying Apple’s Secure Boot chain. Affected Devices and Mitigations Confirmed vulnerable SoCs include: Apple A12 (iPhone XS, XR, iPad Pro 2018) Apple S4/S5 (Apple Watch Series 4/5) Apple A13 (iPhone 11 series) Because BootROM vulnerabilities reside in immutable silicon, no software or firmware update can remediate the issue. Migrating to A14 or later hardware remains the only effective mitigation. Researchers note that Apple’s Secure Enclave Processor (SEP) provides an additional security boundary, though usbliter8 opens broader vectors to attack the Secure Enclave indirectly. Paradigm Shift coordinated disclosure with Apple Product Security prior to publication. The full proof-of-concept exploit is publicly available in their research repository. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates. The post New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise appeared first on Cyber Security News .

cybersecuritynews.com

New MagicAd Android Malware Flood Device With Ads Bypassing Restrictions

New MagicAd Android Malware Flood Device With Ads Bypassing Restrictions

A newly discovered Android trojan called MagicAd has been found flooding infected devices with ads, cleverly slipping past the built-in restrictions of the Android operating system. What makes this threat stand out is not just what it does, but how it does it. It uses multiple techniques to keep showing ads in the background, even after the infected app has been completely closed by the user. The malware was found hiding inside more than 50 games and apps listed on GetApps, the official app store for Xiaomi devices. Each infected app would appear in the store for a short time, usually around a month, then quietly vanish and get replaced by a new one. This rotation strategy appeared to be a deliberate move to avoid early detection, while keeping the threat active on users’ devices long after the app was removed. Dr.Web said in a report shared with Cyber Security News (CSN) that MagicAd first appeared in 2025 and was also found in the Samsung Galaxy Store around that same time. Once an infected app is installed, it continues its malicious activity even if the original upload is pulled from the store . The developers behind these apps have since stopped distributing new infected uploads, but devices already compromised remain at risk. Before jumping into action, the trojan quietly checks whether it is being watched or analyzed. It looks for signs of virtual machines, checks whether the install came through a real user, and verifies the device’s network address against an internal blacklist. If everything looks normal, it hides its own icon from the app menu and sets up silent background services that keep it running at all times. The malware’s reach is not limited to Xiaomi devices. Variants were designed to target Vivo smartphones and Amazon Fire TV devices as well, making it a broader threat than it might initially appear. New MagicAd Android Malware The core trick MagicAd uses is launching ads without ever asking for the permission that normally allows an app to place windows over other apps. Instead, it loads advertising banners as what is called a Translucent Activity, letting them appear on screen without triggering the usual permission checks. On Xiaomi devices, the trojan sends crafted messages called intents to built-in system apps like Mi Browser and Miui SystemUI. These are trusted programs that can receive instructions even when not open, so MagicAd uses them as a relay to push ads onto the screen. On Vivo devices, a similar approach uses Android Binder, a lower-level system channel, targeting iManager, Phonebook, Vivo Browser, and Baidu IME Customized to achieve the same result. Examples of ads displayed by Android.MagicAd.1 (Source – Dr.Web) The most inventive method works across nearly all Android devices regardless of manufacturer. MagicAd decrypts a hidden audio file from its own code, launches the system media player at zero volume, and links it to Android’s global media controls. It then simulates a button press using a background command, which hands control back to the malware so it can silently launch the ad. The user sees an ad appear with no obvious reason why. How It Persists and What Users Can Do MagicAd does not rely on a single method to stay active. It uses a task scheduler to restart its background services on a regular basis, and on older Android versions, it launches a virtual screen to prevent the system from shutting down its components. Even if one method fails, the malware retries before switching to a more direct fallback approach. Users should regularly review unfamiliar apps on their devices and remove anything suspicious or unrecognized. Keeping the device’s operating system updated is also critical, as newer Android versions increasingly block the kind of background behavior MagicAd depends on. A capable mobile security tool that watches for such activity can help detect and remove infections before they cause lasting disruption. Indicators of Compromise (IoCs):- Type Indicator Description Malware Name Android.MagicAd.1 Primary trojan variant distributing background ads  Malware Name Android.MagicAd.1.origin Dex component module used to relay and launch advertisements  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post New MagicAd Android Malware Flood Device With Ads Bypassing Restrictions appeared first on Cyber Security News .

cybersecuritynews.com