fraud

AppWizard
August 7, 2026
Governments are finding it harder to suppress protests through internet shutdowns due to the use of offline messaging applications. Bitchat, an app launched in 2025 by Jack Dorsey, allows devices to communicate via Bluetooth without internet access and gained popularity during recent student protests in New Delhi amid an internet blackout. The Indian government attempted to block access to Bitchat's source code on GitHub, marking a notable first instance of trying to geoblock an open-source repository. On July 26, Bitchat had 430,000 daily active users in India, with 74% of global downloads occurring in the country from July 20 to July 26. The app has been used in various protests globally, including those in Hong Kong, Myanmar, Nepal, Uganda, Madagascar, and Iran. On July 23, the Indian government ordered GitHub to disable access to three Bitchat repositories in India quickly. Jack Dorsey expressed concerns about the Indian government's stance on Bitchat, while digital rights advocates criticized the government's actions as unnecessary. The repositories remained accessible in India and were mirrored on decentralized platforms, complicating removal efforts. India's government has increasingly scrutinized communication platforms based on their design, imposing restrictions on apps like Telegram and WhatsApp.
Tech Optimizer
August 6, 2026
Bitdefender Antivirus Plus is an award-winning security suite for Windows PCs that provides continuous system monitoring and real-time threat detection, effectively blocking viruses, ransomware, phishing attacks, and spyware. A one-year subscription includes features such as Advanced Threat Defense, anti-phishing and anti-fraud protection, ransomware defense, network threat prevention, a vulnerability scanner, anti-tracking tools, and Safepay for secure online transactions. It also offers a built-in VPN with 200MB of encrypted traffic daily. The subscription is available for both new and existing users in Canada and the United States. The current price for a one-year subscription is CAD, reduced from its original price of CAD.
AppWizard
August 4, 2026
A recent analysis by DoubleVerify engineers has identified a trend in mobile advertising known as AfterCall ads, where applications display advertisements immediately after a phone call ends. This practice generates hundreds of millions of impressions monthly and raises concerns about user experience and brand integrity. AfterCall applications operate using three components: a misleading permission, a Broadcast Receiver to capture end-of-call events, and an Activity to display ads. The SYSTEMALERTWINDOW permission allows these apps to show content over others, often granted under false pretenses. They utilize Android's telephony system to trigger ads post-call and employ tactics to obscure their presence, such as removing themselves from the recent apps list and using innocuous icons. Detection is challenging due to the lack of shared codebases and the obfuscation techniques used. The scale of the issue is significant, with numerous AfterCall applications identified monthly, negatively impacting user experience and raising concerns for advertisers.
AppWizard
July 31, 2026
Bitsight's investigation revealed that inexpensive Android TV boxes are being shipped with applications that can change their hardware identity, allowing them to impersonate popular smartphone brands like Samsung and Huawei. This operation, named Fuyao, is linked to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. The H96MAXV11 model was frequently reported among the affected devices. In one day, the operation received 65,957 reports from about 38,000 unique MAC addresses, with many devices misidentified as phones due to spoofed identifiers. Fengwo has also promoted over 120,000 "AI digital humans," though details on this marketing term are vague. The command-and-control server for Fuyao sends phone profiles to devices, masking their actual hardware specifications. The operation uses machine vision technology and a YOLOv8s object-detection model to identify advertisements. Bitsight documented 40 fraud tasks, 21 unique campaigns, and 166 modules across four devices. The operation's payout structure involves 144 operator-owned domains, with an estimated gross return of .25 per device daily, potentially leading to annual revenues in the millions. Attribution to Fengwo is supported by shared TLS certificate data and public patent records, although the patents do not directly address advertising. There is uncertainty about how the fraudulent apps were installed and at what point in the supply chain they were introduced. Device owners are advised to verify Play Protect certification and disconnect suspicious devices.
AppWizard
July 29, 2026
The Federal Security Service (FSB) of Russia has charged Pavel Durov, the founder of Telegram, with facilitating terrorist activities and has issued an international warrant for his arrest. The charges are based on Telegram's alleged failure to remove content used by Ukrainian special services and terrorist organizations linked to sabotage, terrorism, mass killings, and cyber-fraud operations within Russia. Telegram has over 1 billion users and is a key communication tool during the Russia-Ukraine conflict. Durov, who previously founded VKontakte, has lived abroad since 2014 and holds Emirati and French citizenship. He is also under investigation by French authorities for insufficiently addressing criminal activity on Telegram and not cooperating with law enforcement. Durov denies any wrongdoing.
AppWizard
July 29, 2026
Android users experiencing unexpected ads after phone calls are encountering a form of ad fraud linked to applications on the Google Play Store that utilize a tactic called AfterCall. These applications, often benign utility apps, request overlay permissions to display ads over the Android interface. They can launch full-screen advertisements disguised as call information screens after detecting the end of a call. Overlay permissions are categorized as "special permissions" and require users to enable them in system settings, rather than through typical installation pop-ups. Users are advised to check for apps with overlay permissions by navigating to Settings > Apps > Special app access and uninstall any unfamiliar applications. Regular audits of these permissions are recommended to disable unnecessary ones. While these apps primarily serve as an annoyance, they can waste advertising dollars and potentially harm brand reputations.
Tech Optimizer
July 29, 2026
A study by Kaspersky surveyed 7,200 Gen Z individuals across 18 countries and found that only 27% use mobile antivirus software, while 28% regularly back up their phone data. Many have experienced cyberattacks, with 17% reporting hacked social media accounts and 12% losing access to gaming accounts. The study highlights that compromised smartphones can expose sensitive personal information, increasing the risk of identity theft and financial fraud. Kaspersky has introduced an interactive online game, Case 404, to educate Gen Z on recognizing scams and phishing attempts.
AppWizard
July 27, 2026
New Blood has released the second episode, Shadow of Death, for their game Fallen Aces, which is currently on sale until August 8. The game features a blend of stealth, slapstick combat, and a pulpy narrative, and introduces the Mateba Model 6 Unica firearm. New Blood has a history of gradually expanding their games and launching them at lower prices, with Fallen Aces now available at a reduced rate.
AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
Search