Fraudulent Android apps disguise themselves as everyday utilities to abuse the SYSTEM_ALERT_WINDOW system permission and deliberately display ads immediately after phone calls.
Attackers exploit fear of security events to distribute fake apps through fraudulent Play Store replicas and infect Android devices with multi-layered spyware.
Malware RedHook uses the native Wireless ADB development tool on Android to gain full device control without exploiting vulnerabilities and compromise enterprise access – MFA alone does not protect against it.
Android malware RedWing is being offered as a rental service for bank fraud via Telegram and appears to be a variant of the established Oblivion malware.
The four-year-old Popa botnet, used to monetize compromised TV boxes, is traced technically and personally to the Israeli proxy provider NetNut (Alarum Technologies).