Tag
Multiple Vulnerabilities in Samsung Android Implementations
2 TTPsMultiple vulnerabilities in Samsung's Android implementation allow remote or local attackers to achieve arbitrary code execution with root privileges, escalate permissions, and cause denial-of-service.
PanDa Android RAT Campaign Targeting Mexican Financial Users
6 TTPs 12 IOCsChinese-speaking threat actors are using the AppPanda phishing platform to distribute the PanDa Android RAT via Meta Ads, targeting Spanish-speaking users in Mexico to harvest banking credentials.
Unauthenticated Remote Access Vulnerability in ES File Explorer
3 TTPs 1 CVECVE-2019-6447 allows unauthenticated attackers on a local Wi-Fi network to execute arbitrary commands and exfiltrate files from Android devices running vulnerable versions of ES File Explorer.
Q1 2026 Mobile Threat Landscape: SparkCat and Triada Updates
2 rules 1 TTPThe Q1 2026 mobile threat landscape saw a decrease in overall attack volume driven by reduced adware and RiskTool detections, while the number of unique users targeted remained stable, with new SparkCat variants on app stores and increased banking Trojan and Triada backdoor activity.
Samsung Mobile Devices Multiple Vulnerabilities
2 rulesSamsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.