This Android Ransomware Can Watch Your Screen While Demanding Payment

Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.

Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.

Microsoft says a China-focused campaign is rebuilding malicious installers between downloads, making familiar names and file hashes unreliable clues.

A multinational operation redirected Sality's peer-to-peer command traffic into sinkholes after two decades and more than 11 million linked IP addresses.
Nineteen Chrome and Edge extensions delivered wallet-draining and credential-stealing modules, including five legitimate tools weaponised after ownership changes.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

Cruciferra combines ClickFix delivery, a signed vulnerable driver, signed Microsoft binaries and process hollowing to disable endpoint security and deploy an infostealer.

AnonyMousKIT combines stolen-device data, phishing pages and low-cost AI voice agents to obtain the credentials needed to disable Activation Lock.

Attackers used npm packages as storage for fake verification pages rendered through trusted mirrors, turning legitimate CDN domains into phishing infrastructure.

ToxicPanda 2.0 abuses VPN permission to cut off Google Play, then automates Android wireless debugging to obtain shell-level capability. The chain shows how legitimate platform functions can become a post-compromise control path.

SynkLoader used a fake Teams help desk, an Azure-hosted installer, a counterfeit Windows lock screen and an internal proxy to turn one user action into hands-on-keyboard corporate access.