Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Anome Protocol and 4AIBSC Partner to Scale AI-Powered Applications in Web3

June 7, 2026

Crypto Council for Innovation launches coalition to push for regulatory clarity on vaults

June 7, 2026

Why Jito’s 14% rally faces a reality check as JTO netflow turns negative

June 7, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Android Trojan Variant Expands with Ransomware Tactics
New Android Trojan Variant Expands with Ransomware Tactics
Security and Privacy

New Android Trojan Variant Expands with Ransomware Tactics

August 26, 20252 Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new version of the Hook Android banking Trojan has surfaced, showcasing one of the most extensive feature sets ever recorded for mobile malware.

Researchers at Zimperium’s zLabs identified the variant, which now supports 107 remote commands – of which 38 are newly introduced.

The upgraded malware goes beyond financial theft, adopting ransomware-style methods and advanced surveillance tools.

Among its latest functions are:

  • Ransomware overlays that coerce users into making payments

  • Fake NFC scanning prompts designed to steal sensitive data

  • Lock screen bypass using deceptive PIN and pattern screens

  • Transparent overlays for capturing gestures

  • Real-time screen-streaming for full monitoring

“The campaign is operating on a truly global scale,” warned Frankie Sclafani, director of cybersecurity enablement at Deepwatch.

“The detection count has more than doubled in just two weeks, reflecting a rapid and aggressive growth pattern.”

Read more on Android malware threats: Android Malware Targets Banking Users Through Discord Channels

Unlike previous campaigns that relied mainly on phishing sites, Hook’s operators are now spreading malicious APK files through GitHub repositories.

Zimperium reported that other malware families, including Ermac, Brokewell and various SMS spyware strains, are also being distributed this way.

“This phishing campaign is tricky because it personalizes fake websites with the victim’s own email and company logo, making the scam look real,” explained J Stephen Kowski, field CTO at SlashNext.

“The malicious files delivered are not just for stealing passwords but for installing powerful remote access tools that give attackers long-term control.”

Zimperium confirmed Hook also continues to exploit Android Accessibility Services for automated fraud and device control.

See also  Dolomite Expands to Polygon zkEVM: Pioneering DeFi’s Next Frontier

As mentioned above, its most alarming new feature is a ransomware overlay that displays a payment demand with a cryptocurrency wallet address controlled by attackers. Fake credit card forms, mimicking services like Google Pay, are also used to harvest payment information.

Code references found in the Trojan suggest its developers may add RabbitMQ for more resilient command-and-control (C2) communications. There are also traces of Telegram-based functionality under development, though these features remain incomplete.

Zimperium stated that it has collaborated with industry partners to remove at least one GitHub repository associated with distribution of the malware.

The rapid evolution of Hook underscores how traditional banking Trojans are adopting spyware and ransomware tactics.

As Sclafani concluded, “this is a complete attack process designed to secretly install a persistent malicious payload inside your network,” making it a growing concern for enterprises and individuals alike.

Source link

Android Expands Ransomware Tactics Trojan Variant
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Brickken Expands Into Taiko, Boosting RWA Network Scalability, Interoperability With Ethereum L2 Scaling Solution

June 5, 2026

Mastercard expands on-chain settlement in bet on stablecoins and always-on finance

June 4, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

PageUp Expands Partner Ecosystem with Flockity, Vouch, and Certn to Drive Authentic, Integrated Hiring

June 1, 2026
View 2 Comments

2 Comments

  1. https://meinestadtkleinanzeigen.de/ on August 26, 2025 8:15 pm

    This is such a valuable article! ???? I really like how you’ve managed to explain the topic in a clear and practical way—it feels authentic and easy to relate to. Reading it gave me some new perspectives that I can actually apply. I’m especially interested in content like this because at meinestadtkleinanzeigen.de we’re running a classifieds and directory platform in Germany that connects people with services, businesses, and opportunities across many categories. Insights like yours remind me how powerful it is when knowledge and connections come together. Thanks for sharing—looking forward to more of your work! ????

    Reply
  2. explodingbrands.de on August 26, 2025 9:16 pm

    Fantastic read! ???? I really appreciate how clearly you explained the topic—your writing not only shows expertise but also makes the subject approachable for a wide audience. It’s rare to come across content that feels both insightful and practical at the same time. At explodingbrands.de we run a growing directory site in Germany that features businesses from many different categories. That’s why I truly value articles like yours, because they highlight how knowledge and visibility can create stronger connections between people, services, and opportunities.Keep up the great work—I’ll definitely be checking back for more of your insights! ????

    Reply
Leave A Reply Cancel Reply

Top Posts

Redditor’s hacked Bitcoin is a lesson on the hidden dangers of paper wallets

July 27, 2023

Ethereum (ETH) to $20K? What is happening to Bitcoin Cash (BCH) and Pullix?

January 24, 2024

Crypto Hacks and Cyberattacks Fund About 50% of North Korea’s Missile Program: Report

May 19, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Anome Protocol and 4AIBSC Partner to Scale AI-Powered Applications in Web3

June 7, 2026

Crypto Council for Innovation launches coalition to push for regulatory clarity on vaults

June 7, 2026

Why Jito’s 14% rally faces a reality check as JTO netflow turns negative

June 7, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,095.004.22%
  • ethereumEthereum(ETH)$1,680.588.02%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$604.825.77%
  • usd-coinUSDC(USDC)$1.000.02%
  • rippleXRP(XRP)$1.166.62%
  • solanaSolana(SOL)$66.377.70%
  • tronTRON(TRX)$0.3263091.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • dogecoinDogecoin(DOGE)$0.0858715.69%