When malware plays pretend. [Research Saturday]
CyberWire Daily9 Aug 2025

When malware plays pretend. [Research Saturday]

Nicolás Chiaraviglio, Chief Scientist from Zimperium's zLabs, joins to discuss their work on "Behind Random Words: DoubleTrouble Mobile Banking Trojan Revealed." Zimperium’s zLabs team has been tracking an evolving banker trojan dubbed DoubleTrouble, which has grown more sophisticated in both its distribution and capabilities. Initially spread via phishing sites impersonating European banks, it now uses malicious APKs hosted in Discord channels, and boasts features like screen recording, keylogging, UI overlays, and app blocking—all while heavily abusing Android’s Accessibility Services. Despite advanced obfuscation and dynamic evasion techniques, Zimperium’s on-device detection tools have successfully identified both known and previously unseen variants, helping protect users from credential theft, financial fraud, and device compromise. Complete our annual ⁠⁠audience survey⁠⁠ before August 31. The research can be found here: ⁠Behind Random Words: DoubleTrouble Mobile Banking Trojan Revealed

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3747)

RMM-ber this ransomware. [Research Saturday]

RMM-ber this ransomware. [Research Saturday]

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ...

5 Sep 19min

What the Flock?

What the Flock?

The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicatin...

4 Sep 31min

Who’s watching the AI watchers?

Who’s watching the AI watchers?

A watchdog challenges the Trump administration’s secret frontier AI reviews. METR discloses two cyberattacks. Leaked documents reveal a Russian cyber training pipeline. Rogue ScreenConnect clients spr...

3 Sep 24min

Drive-by data theft.

Drive-by data theft.

Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucination...

2 Sep 30min

Nightmare on Windows 11.

Nightmare on Windows 11.

Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-b...

1 Sep 27min

Let’s kill the kill switch.

Let’s kill the kill switch.

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastru...

31 Aug 27min

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and ...

30 Aug 24min

Who let the AI hack? [Research Saturday]

Who let the AI hack? [Research Saturday]

Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using ...

29 Aug 23min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
stopp-verden
popradet
nokon-ma-ga
dine-penger-pengeradet
det-store-bildet
rss-gukild-johaug
rss-espen-lee-usensurert
hanna-de-heldige
fotballpodden-2
bt-dokumentar-2
aftenbla-bla
rss-ness
e24-podden
rss-penger-polser-og-politikk
lydartikler-fra-aftenposten
frokostshowet-pa-p5