proxy

AppWizard
September 19, 2026
A new Android malware called RatHat has emerged, analyzed by researchers from Zimperium's zLabs. It spreads through deceptive smishing texts and malicious ads that lead users to counterfeit download pages for popular apps. Once installed, it manipulates Android's Accessibility Service to gain elevated access by enabling Wireless Debugging and retrieving authentication codes without user intervention. RatHat targets finance and banking apps to steal user IDs, passwords, and MFA codes, using techniques to obtain touch coordinates for PIN recovery. It can intercept SMS messages, gain limited control of the device, and reinstall itself. Users are advised against sideloading apps and granting unnecessary accessibility permissions. Google's Advanced Protection Mode and Malwarebytes for Android can help mitigate risks associated with RatHat.
AppWizard
September 19, 2026
Security researchers have identified an Android banking Trojan named RatHat, which utilizes artificial intelligence, accessibility features, and Android Debug Bridge (ADB) to steal financial credentials, PINs, and one-time passcodes. Unlike traditional malware, RatHat employs a live AI assistant that interacts with the Android accessibility tree, allowing it to make real-time decisions based on the victim's screen content. The infection typically starts with social-engineering tactics, leading victims to counterfeit download pages where they are tricked into sideloading a malicious APK. Once installed, RatHat prompts users to enable Android Accessibility Service permissions, which it exploits to navigate Developer Options and enable Wireless Debugging. This grants it shell-level ADB access, allowing it to bypass application sandbox restrictions. RatHat deploys two native binaries for executing commands and maintaining a connection to the attacker's infrastructure. It targets banking applications through credential-stealing overlays and can intercept SMS messages for transaction verification codes. Additionally, it can record touch coordinates to reconstruct PINs and unlock patterns. RatHat includes persistence mechanisms to restore itself after removal, and users are advised to perform a factory reset if they suspect compromise. To reduce infection risk, users should avoid sideloading apps from unknown links, deny unnecessary Accessibility Service requests, and refrain from enabling Developer Options or Wireless Debugging for unfamiliar applications.
AppWizard
September 18, 2026
Cybersecurity experts have identified a new Android malware named RatHat, believed to be operated by Chinese threat actors. RatHat is distributed primarily through smishing and malvertising campaigns, leading users to deceptive download portals. It employs an automated multi-stage infection process and exploits Accessibility features along with a local ADB self-pairing mechanism to escape the Android application sandbox. The malware uses various anti-analysis techniques, including container tampering, manifest bombs, DEX bytecode poisoning, and dual string-encryption. RatHat's architecture consists of a malicious Android application, a Go agent, and an FRP reverse-proxy client, which together enable it to gain critical system permissions and perform various malicious activities such as credential capturing, screen recording, and SMS interception. Even if uninstalled, the malware retains shell access to the device, allowing attackers to reinstall it. RatHat can serialize the device's Accessibility tree to XML and communicate with a Generative AI assistant for tasks like screen coordinate determination and text extraction. The Go Agent, masquerading as a native library, exploits shell access to execute commands and establish a persistent connection to a command-and-control server via the FRP client. The C2 server can issue extensive commands to collect sensitive information, including SMS messages, credentials, files, and keystrokes, and RatHat also features a hardware-level keylogger.
Tech Optimizer
September 11, 2026
Lakebase Postgres employs a disaggregated storage model that enhances data management through efficient caching, utilizing an object store like S3 for backups. The caching operates on two layers: within distributed storage for optimizing write and read performance, and on the Postgres compute side for ultra-fast access to frequently accessed pages. Traditional Postgres caching involves shared buffers and the OS page cache, which leads to double buffering and inefficiencies. Lakebase Postgres addresses these issues by implementing a local file cache (LFC) and larger shared buffers, allowing for more effective memory utilization without the drawbacks of the OS page cache. The shared buffers are set to a maximum of 1 GB, while the LFC can utilize up to 75% of DRAM. The introduction of huge pages reduces memory management overhead and improves performance, resulting in significant throughput increases and reduced latency in production environments. Recent enhancements have shown up to 2× throughput improvements and substantial reductions in CPU usage. The focus is now on extending these benefits to autoscaling Postgres computes, with plans to implement dynamic shared buffers and autoscaling huge pages.
Winsage
September 4, 2026
Microsoft has identified a new malware campaign called TerminalFix that uses fake CAPTCHA prompts to trick Windows users into executing malicious commands. This campaign is a variation of ClickFix attacks and employs deceptive pages that impersonate reputable services like Cloudflare. Instead of traditional CAPTCHA challenges, users are instructed to open PowerShell or Command Prompt and paste in commands, allowing attackers to execute complex scripts more easily. TerminalFix initiates a multi-stage intrusion, granting attackers persistent proxy access to the infected machine, which can lead to further exploitation of the company's network. The campaign relies on social engineering tactics, requiring user compliance with counterfeit verification instructions. Microsoft has released mitigation guidance, recommending restrictions on PowerShell access, monitoring for DLL sideloading, blocking outdated Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. The campaign poses significant risks to enterprise networks, but individual users should also be cautious about executing commands requested by websites.
Winsage
September 1, 2026
Microsoft Threat Intelligence has identified a new variant of the ClickFix malware campaign called "TerminalFix." This variant uses deceptive CAPTCHAs that mimic trusted services like Cloudflare and directs users to PowerShell or a command prompt, allowing for the execution of complex scripts. TerminalFix aims to orchestrate a multi-stage attack that provides attackers with persistent, network-level proxy access through the compromised host, potentially leading to significant data theft and malware propagation within unsecured enterprise networks. Recommendations for defense against TerminalFix include restricting access to PowerShell and Windows Run dialogs, monitoring for DLL sideloading indicators, blocking Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. The attacks primarily target enterprise environments rather than individual consumers.
AppWizard
August 26, 2026
Multilogin has launched an open-source AI agent for social media management on authentic Android devices in the cloud. This tool enables automation of workflows on platforms like TikTok, Instagram, Facebook, and X. The AI agent connects to a Multilogin Android cloud phone, allowing it to view screens, execute taps, type commands, and save results. It integrates with multiple AI agents capable of running shell commands and interpreting visual inputs. Each cloud phone functions as an independent Android device with unique parameters and persistent app data, connected via ADB. The tool monitors the cloud phone's readiness, activates ADB, interprets screenshots, and executes tasks while logging activities. It is designed for marketers, agencies, creators, and teams, providing setup instructions and compatibility with AI tools like ChatGPT/Codex and Claude Code. The project is available on GitHub, and Multilogin offers a free plan with paid options starting at [openai_gpt model="gpt-4o-mini" prompt="Summarize the content and extract only the fact described in the text bellow. The summary shall NOT include a title, introduction and conclusion. Text: Multilogin has unveiled an innovative open-source AI agent designed to empower social media management on authentic Android devices hosted in the cloud. This groundbreaking tool bridges the gap between AI capabilities and mobile app functionalities, allowing users to automate workflows across popular platforms such as TikTok, Instagram, Facebook, and X. How the Tool Functions The newly developed AI agent connects seamlessly to a Multilogin Android cloud phone, providing it with the ability to view screens, execute taps, type commands, and complete various tasks while saving the results. This integration works harmoniously with multiple AI agents, including Claude Code, Cursor, and OpenClaw, all of which can run shell commands and interpret visual inputs from screenshots. As many social media operations increasingly shift to mobile applications, the limitations of browser-based tools become apparent. While browser profiles serve their purpose for web-based tasks, they fall short when it comes to executing native Android applications. Multilogin's cloud phones offer a distinct advantage by providing an authentic Android environment, facilitating direct interaction with mobile apps. Each cloud phone operates as an independent Android device in the cloud, complete with unique device parameters, installed applications, and persistent app data. The AI agent connects to the cloud phone via ADB (Android Debug Bridge), a standard interface used by developers for device management. Operational Efficiency and Flexibility The process begins with the selection of an Android cloud phone, which the tool monitors until it is fully operational. Once ready, the AI agent activates ADB, allowing it to interpret screenshots, determine subsequent actions, and execute tasks such as tapping or typing. Upon completion of a task or in the event of an error, the tool halts the cloud phone and logs the activity, ensuring that resources are not wasted during the development and testing of AI-assisted mobile workflows. This project is compatible with any AI agent capable of executing shell commands and processing visual inputs, making it versatile for various applications. Gleb K., the UI team lead at Multilogin, emphasizes the importance of this development: “AI agents are becoming useful for real operational work, but many important workflows still happen inside mobile apps. We built this open-source project to give everyone a simple and controlled way to connect AI agents to Android cloud phones.” Target Audience and Accessibility The cloud phone agent is tailored for marketers, agencies, creators, and teams seeking an AI assistant to streamline routine tasks within Android applications. Users need not start from scratch; the project provides clear setup instructions and is compatible with widely-used AI tools such as ChatGPT/Codex, Claude Code, OpenClaw, and Cursor. Once connected, the AI agent can efficiently manage tasks on the cloud phone, with the Multilogin Support team readily available for assistance. As with any automation tool, users are encouraged to adhere to the guidelines set by the applications they utilize. The Multilogin cloud phone agent is accessible on GitHub: GitHub Repository. For further information about Android cloud phones from Multilogin, visit Multilogin's Website. The Need for Android Cloud Phones in Social Media Workflows As marketing teams increasingly adopt AI-driven workflows, the necessity for reliable and scalable environments becomes paramount. Real Android devices provide AI agents with the authentic conditions that mimic human usage, allowing accounts to behave naturally and accumulate history over time—an aspect that emulators and browser profiles simply cannot replicate. About Multilogin Multilogin is a comprehensive platform offering cloud phones and browser profiles tailored for marketers, agencies, creators, and AI workflow builders. It enables teams to manage distinct browser and mobile workflows from a unified dashboard. Multilogin offers a Free plan with no credit card requirement, while paid plans commence at .08 per month when billed annually, inclusive of monthly proxy traffic and mobile minutes based on the selected plan. Established in 2015, Multilogin operates from the UAE and adheres to GDPR compliance. Media Contact: Teona B. Media Specialist Multilogin Email: marketing@multilogin.com For additional visuals accompanying this announcement, please visit the following links: Visual 1 Visual 2" max_tokens="3500" temperature="0.3" top_p="1.0" best_of="1" presence_penalty="0.1" frequency_penalty="frequency_penalty"].08 per month.
Tech Optimizer
August 20, 2026
Surfshark offers a cybersecurity package called Surfshark One, which includes antivirus capabilities and a VPN service. The overall rating for Surfshark is 4.1/5, with specific ratings of 3.7/5 for protection, 4.5/5 for performance, 3.3/5 for features, 5.0/5 for support, and 4.5/5 for value. The antivirus component has a 93.44% malware detection rate and a 95% phishing detection rate with no false alarms. Surfshark One costs .79 per month and includes features like real-time protection, scheduled scans, breach alerts, a private search engine, and webcam protection. The One+ tier adds Incogni data removal and identity theft insurance. Surfshark Antivirus is not available as a standalone product and lacks features such as a firewall, password manager, and parental controls. It is compatible with Windows, macOS, and Android. Surfshark provides a 30-day money-back guarantee on all plans.
Search