A study by Proton found tracker code associated with companies in China and Russia in many of the most downloaded free Android games in the US and Europe.
The Max messenger, developed by VK, has significant user tracking capabilities. A report from InterSecLab revealed that:
- Max's features can vary for individual users without app updates.
- It lacks end-to-end encryption, allowing VK access to messages, even in "secret chats."
- Each account can be configured to perform specific actions, such as decrypting messages on VK's servers and blocking messages if a VPN is detected.
- Upon launching, Max reports the user’s network environment to VK, including their public IP address and mobile carrier.
- The app uploads users’ entire address books unencrypted to VK's servers, accessing contacts of non-registered individuals.
- A phone number query can reveal extensive user information without notification.
- Max stops functioning if it detects a VPN, requiring users to disable it to send messages, although workarounds exist.
- New users receive a curated list of recommended channels, primarily featuring state media and pro-government figures.
A keylogger captures every keystroke made on a device and sends that information to an external source. In 2025, infostealer malware, including keyloggers, resulted in the theft of 642.4 million credentials from 13.2 million infections globally. In Australia, approximately 30,000 banking passwords were compromised between 2021 and 2025 due to this malware. The Australian Cyber Security Centre reported over 42,500 calls related to credential theft in one year, a 16% increase. Four main malware families dominate the landscape, with LummaC2 accounting for nearly 60% of credentials linked to infostealers in 2026. Keyloggers can be detected through signs such as typing lag, unexpected antivirus notifications, new browser extensions, and unexplained spikes in outbound data usage. Detection and removal steps include checking running processes, auditing startup programs, reviewing installed programs, running antivirus scans, and resetting passwords from a clean device. Keyloggers can infiltrate systems via phishing emails, malicious attachments, or compromised software downloads. Mobile devices can also be targeted by keyloggers disguised as legitimate apps.
Malicious Android applications are being promoted through social media advertisements, particularly on platforms like Instagram and Facebook, posing significant risks to users. The Indian Cyber Crime Coordination Centre (I4C) has warned about deceptive apps advertised under names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nezo, and Vixa, which often redirect users to pornographic websites to download APK files. These applications can exploit sensitive device permissions, leading to malware infections, unauthorized financial transactions, and various forms of cyber fraud. Users may be tricked into granting accessibility permissions that allow the malware to operate in the background and potentially install a VPN, rerouting internet traffic through servers controlled by attackers. Cybersecurity experts advise users to verify the legitimacy of applications before installation and to be cautious of permissions requested by unknown apps.
A free VPN for Android can improve internet privacy, especially on untrusted networks, but it has limitations, such as not guaranteeing complete anonymity or security. The VPN creates an encrypted tunnel between the device and the server, protecting traffic from local monitoring but not ensuring overall security if poorly implemented. Changing your IP address does not guarantee anonymity, as account logins and tracking technologies can still identify users. Free VPNs may be suitable for low-risk tasks, like occasional browsing on public Wi-Fi, but they do not protect against malware or phishing. Providers often rely on alternative revenue sources, such as advertising or data sharing, which necessitates careful examination of their privacy policies. Free VPNs may have limitations like data caps, slower speeds, and fewer server options compared to paid services. Users should evaluate the provider’s background, privacy policy, permissions, and performance before installation. A paid VPN generally offers better reliability, support, and transparency, making it a safer choice for sensitive activities.
Elastic Security Labs has identified four previously undocumented programs associated with REVSTEALER, a Windows information stealer that persists on infected machines after self-deletion. The programs are ProManager, WinUpdate, SoftManager, and LockAppHost, each with distinct functionalities. ProManager steals wallet files and logs passwords, WinUpdate monitors the clipboard for cryptocurrency addresses, SoftManager acts as a reverse proxy, and LockAppHost executes a cryptocurrency miner after disabling Windows Update and Microsoft Defender.
REVSTEALER has been marketed as a commercial infostealer since February 2026, exfiltrating sensitive data such as browser passwords, cookies, and cryptocurrency wallet information. It deletes itself after reporting its activities but leaves the four programs installed for persistence. These programs share build tradecraft with REVSTEALER, including the use of identical packers and runtime function resolutions.
REVSTEALER primarily spreads through game-cheat lures and disguises itself as pirated software. It employs evasion techniques to resist analysis, including checking for sandbox environments and using indirect system calls. Users are advised to avoid unofficial software and to follow specific steps if infected, such as re-enabling Windows Update services and changing passwords.
Indicators of compromise include SHA-256 hashes for REVSTEALER and its associated programs, as well as domains linked to their command and control servers.
Scammers are exploiting the Indeed platform to target job seekers by using counterfeit Android "interview" applications. Users in the UK and Brazil reported being instructed by supposed employers to download fraudulent apps like MyInterview, which compromised their devices. These scammers post fake job listings and prompt applicants to install apps that mimic Indeed's login page and establish a VPN connection. The malicious apps, classified as Trojan.Droppers, can install additional untrusted software and gain control over devices, complicating uninstallation efforts. Indeed confirmed that their interview process does not require downloading any separate app and warned job seekers against such scams. Indicators of compromise include specific MD5 hashes and package names associated with the Trojan droppers and dropped malware payloads.
Malware researcher Dominik Reichel has discovered a sophisticated Windows backdoor named Sleepwalker, which remains dormant in memory until activated by a specially crafted network packet. Sleepwalker uses a 23-instruction command language to execute tasks, including running code in memory and exfiltrating data. It activates through a proprietary activation packet that does not contain readable commands. The malware targets a VMware VMCI and disguises itself as Microsoft's dpapi.dll, mimicking its functions while redirecting calls to a non-existent file. Once it confirms its host process as ERAAgent.exe, it enters a dormant state to evade detection. Sleepwalker monitors for a specific pattern known as a magic packet to decrypt and interpret commands. Commands sent to it are encrypted with AES-256-CCM and must be read in a specific order. The backdoor includes functionalities for sending and concealing data, receiving tasks, and executing programs. Reichel has developed a toolkit to decode Sleepwalker’s bytecode and a mitigation guide for affected users. However, there are significant gaps in knowledge regarding the initial access method, victim identification, and the malware's operator.
Threat actors are exploiting FTP banners to conceal commands for deploying two undocumented remote access trojans (RATs), E4del and PINHOLE. This method was first observed by MalwareHunterTeam in July 2026, using shortcut files (.LNK) and FTP server banners as dead-drop resolvers to retrieve malicious commands. SOCRadar confirmed that this technique has been weaponized since early July 2026 and remains active, with new infrastructure identified as recently as August 2026. The attacks typically start with a ZIP archive leading to an LNK-based infection chain, likely initiated through phishing tactics.
E4del is a Node.js-based RAT disguised within a digitally signed Electron application mimicking Discord, capable of executing commands, capturing screenshots, streaming desktops, and downloading additional payloads. It also includes a module for privilege escalation. PINHOLE retrieves its command and control configuration from Pinterest and SurveyMonkey, designed to leave a minimal footprint and employing shellcode fluctuation. It supports 14 commands, including file management and credential theft, but had only recorded 11 execution events at the time of analysis.
SOCRadar notes that while using FTP banners is a novel approach, it is less stealthy than traditional web-based dead-drop resolvers. They provide indicators of compromise to help identify malicious infrastructure and infected machines.
Threema experienced significant disruptions due to large-scale DDoS attacks, rendering the service inaccessible for several hours on Tuesday and causing intermittent outages on Wednesday morning. The attacks targeted both Threema and its Swiss colocation partner, Nine, with service being unavailable from 7:30 p.m. to 11:30 p.m. CEST on Tuesday. By 12:23 p.m. on Wednesday, normal operations were restored. The security of Threema's systems and user data remained intact despite the service availability issues. The nature of the attacks made mitigation challenging, as attackers modified their methods rapidly. Threema's status page faced issues during the outage, and communication was conducted via email and social media. In response, Threema is implementing specialized upstream DDoS protection and plans to enhance its status page to provide monitoring for future disruptions.