43932
Mobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com
Bypassing Android Hardware Attestation from the Analyst's Chair
https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
Striking gold: Inside the GoldDigger Android malware
https://www.ibm.com/think/security/golddigger-android-malware-analysis
Dropping Elephant (Patchwork): Espionage APT Tactics and Tools
https://www.picussecurity.com/resource/blog/dropping-elephant-patchwork-espionage-apt-tactics-and-tools
Zero-Click File Drop on Xiaomi ShareMe (MiDrop)
https://blog.byterialab.com/zero-click-file-drop-on-xiaomi-shareme-midrop/
Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/
Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT
https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/
Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post
https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post
Reading Contact Photos Without READ_CONTACTS: A Google Messages Confused Deputy Bug
https://blog.devploit.dev/posts/google-messages-avatarcontentprovider-contacts-bypass/
How to Bypass mTLS on Android with Frida
https://kiratliygt.medium.com/how-to-bypass-mtls-on-android-with-frida-45c5e71373e8
RedWing: A Mobile Malware-as-a-Service Operation
https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation
Android 17 root: full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702)
Click on the link -> root Android
https://x.com/nebusecurity/status/2069707520160227688
Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support
https://github.com/UltraSina/androidReverse
Rokarolla : Android Banker with Complete Device Takeover Capabilities
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
I tested Nearby Glasses app to detect "spy" smart glasses - I explained why it is not working reliably and how the app can be even spoofed with fake Bluetooth signals
https://www.mobile-hacker.com/2026/06/14/smart-glasses-can-record-you-and-detecting-them-isnt-so-simple/
Tested the raw socket layer of a pre-production POS system. Found 4 critical/high vulnerabilities — including a replay attack, cross-merchant IDOR, ghost transactions, and card identity bypass
https://m4kr0.vercel.app/posts/iso-8583-under-fire-finding-vulnerabilities-in-a-payment-socket
Kimwolf v7: An Evolution of the Kimwolf Android Botnet
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
Introducing MobHunt: agentic mobile bug bounty hunting
Blog: https://ivrodriguez.com/introducing-mobhunt/
Tool: https://github.com/ivRodriguezCA/MobHunt
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
Root My Pixel: is an Android application designed to automate root access on Google Pixel 10 devices leveraging the NebuSec IonStack exploit (CVE-2026-43499) and integrating ReSukiSU / KernelSU
https://github.com/alex193a/Root-My-Pixel
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
List of 140 vulnerabilities in Samsung preinstalled Android apps reported in 2022
https://github.com/oversecured/Samsung_Vulnerabilities
RedHook Android malware abuses ADB Wireless Debugging and Shizuku to get shell-level privileges
https://www.group-ib.com/blog/redhook-android-rat-upgraded/
GoldPickaxe Returns: When Your Biometric Information is as Important as Your Money
https://zimperium.com/blog/goldpickaxe-returns-when-your-biometric-information-is-as-important-as-your-money
Glitch SPY: New Android RAT Distributed Through a Fake Polish Rental App
https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/
Android Malware Disguised as Document Reader Reaches 100K Downloads on Google Play | Anatsa banker
https://x.com/Threatlabz/status/2069190345418854810
[slides] OffensiveCon 2026: Tile-Based Deferred Rooting: When Your GPU Starts Rendering To Kernel Code Space! (CVE-2025-25180)
https://androidoffsec.withgoogle.com/slides/art_imagination_gpu_offensivecon_2026.pdf
Local Privilege Escalation (LPE) vulnerability in MEmu Android Emulator 9.2.7.0 (CVE-2026-36213)
https://github.com/sec-zone/CVE-2026-36213
FirefUXSS 0-day: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition - not patched yet
https://github.com/v12-security/pocs/tree/main/firefox
NFCShare evolves: from a banking phishing APK to a GitHub-hosted Android NFC fraud campaign
https://www.d3lab.net/nfcshare-evolves-from-a-banking-phishing-apk-to-a-github-hosted-android-nfc-fraud-campaign/