43932
Mobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
1-click could expose every contact saved on your Android, even if you never gave permission to access them (CVE-2026-28576)
Blog: https://www.mobilehackinglab.com/blog/cve-2026-28576-contacts-provider-sqli
Demo: https://www.youtube.com/shorts/nWzdx0uuULM
PoC APK: https://github.com/mobilehackinglab/CVE-2026-28576-poc
Your photos can be accessed without unlocking your Android when you receive a WhatsApp video call [not fixed]
https://www.mobile-hacker.com/2026/09/02/whatsapp-lets-you-view-photos-without-unlocking-smartphone/
Reproducing the Acode Zero-Day Vulnerability
-ACode is a simple code editor for Android
sal/Reproducing-the-Acode-Zero-Day-Vulnerability">sal/Reproducing-the-Acode-Zero-Day-Vulnerability" rel="nofollow">https://hackmd.io/@sal/Reproducing-the-Acode-Zero-Day-Vulnerability
PolicyGapper: A Multi-Prompt LLM-Based App Privacy Compliance Analysis
https://github.com/Mobile-IoT-Security-Lab/PolicyGapper
JADX MCP: a MCP (Model Context Protocol) server as a jadx-gui plugin
https://github.com/0xdad0/jadx-mcp
Malware targeting Android-based automotive head units spread through built-in firmware updates (botnet proxy malware)
https://securelist.com/android-head-unit-malware/121106/
GhostBat RAT: 78 Victims, One Lazy Key, and a Firebase Named After India’s Ruling Party
singhbkn07/78-victims-one-lazy-key-and-a-firebase-named-after-indias-ruling-party-62cf0ad0380e">singhbkn07/78-victims-one-lazy-key-and-a-firebase-named-after-indias-ruling-party-62cf0ad0380e" rel="nofollow">https://medium.com/@singhbkn07/78-victims-one-lazy-key-and-a-firebase-named-after-indias-ruling-party-62cf0ad0380e
ToxicPanda 2.0, a Significantly More Powerful Android Banking Trojan
https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile
A critical vulnerability has been identified that allows arbitrary code execution with kernel privileges affecting Xiaomi Redmi A5 and Motorola E13 devices requiring only the ability to place a video call
https://ssd-disclosure.com/unisoc-t612-lpe/
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps
LSPosed module for disabling SSL certificate pinning on Android
https://github.com/0xdad0/ssl-kill-switch-lsposed
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Vwork: Weaponized Open-source Software as an Addon for Gigabud
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
TeleGapper is a black-box dynamic analysis tool for Telegram Mini Apps on Android devices
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
How to Copy and Backup RFID Access Cards and NFC Key Fobs with Chameleon Ultra
https://www.mobile-hacker.com/2026/09/07/chameleon-ultra-guide-to-rfid-reading-emulation-and-testing/
Uncovering StreamRat: From Meta Ads to Full Device Takeover
https://www.threatfabric.com/blogs/from-meta-ads-to-full-device-takeover-uncovering-streamrat
Beware of fake Indeed interview apps used to install spyware
https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware
How to Install Proxmark3 on the uConsole to read, write and clone some of RFID and NFC tokens
https://www.mobile-hacker.com/2026/08/31/how-to-install-proxmark3-on-the-clockworkpi-uconsole/
Mesh network cache poisoning: exploiting BitChat's BLE authentication
Blog: https://barghest.asia/blog/bitchat-cache-poisoning/
PoC: https://github.com/BARGHEST-ngo/PoC_Bitchat1.15.0_iOS-BLEcache-poisoning
Manic: Blend between Banking Malware & Spyware
https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware
Can Someone Secretly Scan Your Payment and Access Card? I Tested It
Blog: https://www.mobile-hacker.com/2026/08/20/how-easy-is-it-to-scan-a-contactless-payment-and-access-card/
Video: https://youtu.be/pwzMFQLrTHU
Porting ghostlock (CVE-2026-43499) to the Samsung Galaxy A17: KDP, DEFEX, and the art of not panicking
https://www.mobilehackinglab.com/blog/cve-2026-43499-ghostlock-a17-root-shell
Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network
https://www.computerweekly.com/news/366649396/Revealed-Cyber-spies-used-malware-from-GitHub-to-hack-EncroChat-cryptophone-network
WindRelay paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out.
https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
LLM Obfuscation Detection Framework for Android Apps
https://github.com/Mobile-IoT-Security-Lab/LLMObfuscDetection