Chinese authorities fraudulent Android app remediation advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Chinese authorities issued June 18, 2026 removal and account-protection guidance for a fraudulent Android app that could steal payment data and remotely control devices in China. Users who installed the app were told to remove it, scan their devices, and change affected passwords. The advisory also urged people to freeze payment channels if funds moved and report the incident to police.
Related Happenings
Flying Eagle Android RAT framework distribution through Telegram
Malware Activity
H score27
First: 29.07.2026 10:07
Last: 29.07.2026 10:07
Sources 1
How related:
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels.
About this happening:
The Flying Eagle Android RAT framework is circulating through criminal Telegram channels, widening access to a kit that can steal payment passwords, log keystrokes...
Flying Eagle Android RAT framework distribution through Telegram
Malware ActivityHow related: Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels.
About this happening: The Flying Eagle Android RAT framework is circulating through criminal Telegram channels, widening access to a kit that can steal payment passwords, log keystrokes...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
BTMOB Android RAT no-code builder malware activity
Malware Activity
H score28
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
Latest development: 29.05.2026 00:10
BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.
Trapdoor Android malvertising and ad-fraud campaign
Campaign
H score39
First: 19.05.2026 19:38
Last: 19.05.2026 19:38
Sources 1
About this happening:
The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...
Trapdoor Android malvertising and ad-fraud campaign
CampaignAbout this happening: The Trapdoor campaign is a self-sustaining malvertising and ad-fraud operation targeting Android users and turning app installs into revenue through threat-actor-contr...
FakeWallet Apple App Store wallet-stealing apps
Malware Activity
H score8
First: 21.04.2026 00:52
Last: 21.04.2026 00:52
Sources 1
About this happening:
The FakeWallet app set turned the Apple App Store into a delivery channel for 26 malicious wallet lookalikes, putting crypto holders at risk of account takeover and th...
FakeWallet Apple App Store wallet-stealing apps
Malware ActivityAbout this happening: The FakeWallet app set turned the Apple App Store into a delivery channel for 26 malicious wallet lookalikes, putting crypto holders at risk of account takeover and th...
Timeline
-
29.07.2026 10:07 2 articles · 1h ago
Chinese authorities warn users to remove a fraudulent Android app and reset affected accounts
Legal Policy Action UpdateChina's National Cybersecurity Notification Center warned on June 18, 2026 that a fake "公安一网通办" Android application distributed from 110gongan[.]com and associated with 207.56.30[.]188 could steal payment data and remotely control devices. Chinese authorities advised anyone who installed the fraudulent application to remove it, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to police.
Show sources
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates — thehackernews.com — 29.07.2026 10:07
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates — thehackernews.com — 29.07.2026 10:07