Find notable cyber news and cases, enriched with sources, timelines, and signals.

Chinese authorities fraudulent Android app remediation advisory

Advisory/Mitigation
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control devices in China. Users who installed the app were told to remove it, scan their devices, and change affected passwords. The advisory also urged people to freeze payment channels if funds moved and report the incident to police.

Related Happenings

Flying Eagle Android RAT framework distribution through Telegram

Malware Activity
H score27 First: 29.07.2026 10:07 Last: 29.07.2026 10:07 Sources 1

How related: Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels.

About this happening: The Flying Eagle Android RAT framework is circulating through criminal Telegram channels, widening access to a kit that can steal payment passwords, log keystrokes...

RedWing Android spyware rented through Telegram

Malware Activity
H score21 First: 08.07.2026 18:30 Last: 08.07.2026 18:30 Sources 1

About this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

Trapdoor Android malvertising and ad-fraud campaign

Campaign
H score39 First: 19.05.2026 19:38 Last: 19.05.2026 19:38 Sources 1

About this happening: The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...

FakeWallet Apple App Store wallet-stealing apps

Malware Activity
H score8 First: 21.04.2026 00:52 Last: 21.04.2026 00:52 Sources 1

About this happening: The FakeWallet app set turned the Apple App Store into a delivery channel for 26 malicious wallet lookalikes, putting crypto holders at risk of account takeover and th...

Timeline

  1. 29.07.2026 10:07 2 articles · 1h ago

    Chinese authorities warn users to remove a fraudulent Android app and reset affected accounts

    Legal Policy Action Update

    China's National Cybersecurity Notification Center warned on June 18, 2026 that a fake "公安一网通办" Android application distributed from 110gongan[.]com and associated with 207.56.30[.]188 could steal payment data and remotely control devices. Chinese authorities advised anyone who installed the fraudulent application to remove it, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to police.

    Show sources