🚨 A new wave of #NFCShare infections is targeting banking customers across Europe.
Distributed through fake banking app updates hosted on GitHub, NFCShare tricks victims into providing their #banking credentials, reading payment card data via NFC, and entering their PIN. The stolen information is then used in NFC relay payment fraud schemes.
The original NFCShare sample has been tracked on #Koodous since January 2026:
https://t.co/zrS1QFC5Eu
https://t.co/ks6U95Ve61
#CyberSecurity #ThreatIntel #Fraud #Android #Malware #NFC
🚨 BTMOB RAT, the Android MaaS lowering the barrier to full device takeover.
Phishing, fake apps and Accessibility abuse to gain control 📲.
Steals PINs, records screen, logs keys, targets banking apps 💳
No code builder, from $700 per month 💰
Tracked on #Koodous since day one 👇
https://t.co/uWWLyWV1b9
https://t.co/dnG2y541Zn
🚨 NEW Android RAT alert: Mirax
Hit 220,000+ accounts via Meta ads, targeting Spain, disguised as IPTV / sports streaming apps.
🏦 Targets 182 banking & crypto apps using HTML overlays
🔁 NEW: turns infected phones into SOCKS5 residential proxy nodes
Mobile banking trojans are now doubling as proxy botnets. The convergence is here.
Sold as private MaaS, $2,500/3mo. Hosted on GitHub. Hash-rotated daily to dodge detection.
🔗Dropper:
https://t.co/JRUT5jeMbM
https://t.co/EM3wwSFJ8u
🔗Implant:
https://t.co/62H3cWHoCx
https://t.co/1VxB9BsF0Y
#AndroidMalware #Mirax #BankingTrojan #ResidentialProxy #Koodous
🚨 NEW THREAT: "Perseus", a new Android banking malware that reads your NOTES.
Built on Cerberus/Phoenix code, it disguises as IPTV apps and can:
🔍 Scan all your notes
📱 Full device takeover via Accessibility Services
🎭 Overlay attacks on banking & crypto apps
🛡️ Advanced anti-analysis
Targets: Turkey, Italy, Poland, Germany, France, UAE, Portugal + crypto wallets.
Developers likely used LLMs to build it. The game keeps evolving.
We had this Perseus payload on Koodous before it made headlines. Early access to samples is what community-driven intelligence looks like:
🔗 Sample details: https://t.co/3ueOYAlR6O
#AndroidMalware #Perseus #MobileSecurity #ThreatIntelligence #Koodous
Zimperium just published their research on #ArsinkRAT, but at @koodous_project we've had over 1,000 samples from this campaign detected for months, available for community analysis.
Here are some examples:
🔗https://t.co/GCys0nQ2HP
🔗https://t.co/bx4cTccEVu
🔗https://t.co/7iTSHVuSIb
☁️ A massive #Android RAT operation is hiding inside #Google's own infrastructure.
"Arsink" abuses Firebase, Google Apps Script, and Google Drive as C2 channels, making its traffic look like normal cloud activity.
It steals SMS (including OTPs), contacts, call logs, location, and media files. It impersonates dozens of popular brands and distributes via Telegram, Discord, and MediaFire.
🔍Even after Google's takedown, it keeps coming back with new variants.
#AndroidSecurity #Malware #Koodous #ThreatIntelligence #Google
🚨 FvncBot, SeedSnatcher and the upgraded ClayRat variant are a wake-up call: mobile banking and crypto “security” often looks safer in marketing than in real life.
Attackers evolve in weeks. App stores, banks and wallets still respond in months.
If we want to keep up, crowdsourced Android threat intelligence isn’t optional, it’s the baseline. 🔐
#Android #Malware #CyberSecurity #Koodous
⚠️New Android RAT “Fantasy Hub” sold as Russian MaaS uses fake Google Play pages, a Telegram bot and powerful SMS abuse to hijack devices and drain bank accounts. Tracking samples with the community on Koodous.
👇More details in the article below #AndroidMalware #MalwareAnalysis #ThreatIntel
https://t.co/z87jJNXziu
🚨 New threat alert! 🚨 Researchers unveiled #Pixnapping, a novel class of attacks allowing a malicious Android app to stealthily leak information displayed by other apps or websites.
This attack exploits Android APIs and a hardware side channel. It can steal 2FA codes (e.g., from Google Authenticator in under 30 seconds), chat messages, and emails.
Key details:
* Affects nearly all modern Android devices, demonstrated on Google/Samsung phones
* The malicious app requires NO Android permissions
* Tracked as CVE-2025-48561
Read the paper: https://t.co/02i06qwpnS #AndroidSecurity #InfoSec #Cybersecurity
New Android banking trojan on the loose: Klopatra. Aimed at stealing creds & taking over devices. We’ve already spotted multiple samples on Koodous. Dive in, hunt, and tag to help the community—search Klopatra on Koodous now. #AndroidMalware #ThreatIntel #BankingTrojan #RAT
Some samples in #koodous https://t.co/e87hQypQw3 https://t.co/oJ8cydeRAV
🔍 How does Koodous Mobile work?
Protect your device through real-time, collaborative security:
1️⃣ Download the app
2️⃣ Koodous analyzes your apps
3️⃣ Compares with our community database
4️⃣ Detects malicious behavior
5️⃣ Gets alerts
6️⃣ Contribute to the global repository
🚀 Mobile security made simple.
#CyberSecurity #Koodous #antivirus
New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits
More information: https://t.co/YLujurQclZ
#android#Malware#koodous#NFC#malwarebanking
You can find sample examples:
https://t.co/ZzUJaV2mDr
https://t.co/ktUGDbD5kd
https://t.co/WlfA7l0rBz
https://t.co/dPXql2dC8h
@quironsalud penoso en la gestión de sus sistemas informáticos, es rara la vez que en urgencias funciona todo como debe. Tres horas esperando porque el sistema de cita internas de urgencias no funcionaba cuando llegué. Así que caí en el limbo y cualquier prueba analítica pasa a ser de las últimas #penoso #quironmalaga