Google Play is a technology platform tracked across 39 threat clusters and 54 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 18, 2026.
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
Oblivion RAT is a sophisticated Android remote access trojan (RAT) sold as a Malware-as-a-Service (MaaS) platform. It operates on a subscription model, providing threat actors with tools like a web-based APK builder and…
Cloudflare has classified the Russian messaging app MAX, associated with the domain max.ru, as spyware due to its potential for covert data collection and transmission. This designation follows reports of unusual…
The NoVoice Android malware has been discovered on Google Play, hidden in over 50 apps that have been downloaded more than 2.3 million times. This malware, identified by McAfee, exploits 22 vulnerabilities in older…
WhatsApp has alerted approximately 200 users, primarily in Italy, about a malicious version of its app that contained spyware developed by the Italian firm SIO. The fake app was distributed through deceptive means,…
In May 2026, a critical Android vulnerability (CVE-2026-0073) was disclosed, allowing remote device takeover without user interaction. This flaw, linked to the Android Debug Bridge, affects devices with ADB enabled,…
Zimperium's zLabs has reported a significant increase in Android Banking Trojan activity, identifying four distinct campaigns: RecruitRat, SaferRat, Astrinox, and Massiv. These campaigns utilize advanced…
In Q1 2026, Kaspersky reported over 2.67 million mobile attacks, with a significant rise in banking Trojans. The number of unique users targeted remained stable despite a drop in total attacks. Banking Trojan packages…
ESET Research has identified a new variant of the NGate malware family that targets Android users in Brazil by embedding malicious code in a trojanized version of the HandyPay app. This malware allows attackers to…
San Francisco City Attorney David Chiu has ordered Apple and Google to remove 13 AI-powered 'nudify' apps from their app stores, which generate non-consensual deepfake images. The cease-and-desist letters highlight the…