thehackernews.com
·
Sep 25
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution…
A new Android banking trojan, RemControl, has been uncovered targeting retail banking customers in Western Europe, the Middle East and Canada. Distributed via counterfeit Google Play pages masquerading as the TVTap IPTV app and promoted through Meta ads, the malware exploits Android’s Accessibility Service to overlay phishing screens on legitimate banking apps, stream screens, log keystrokes and grant operators full remote control. Command‑and‑control addresses are resolved through an encrypted Telegram dead‑drop, and AI‑assisted code appears in the phishing overlays, with Russian‑language comments suggesting a Russian actor possibly linked to the Medusa UNKN affiliate botnet. Meanwhile, Chinese AI firm Z.ai disabled a ZCode feature after it was found automatically uploading users’ local code repositories to Alibaba Cloud, echoing earlier incidents with SpaceXAI’s Grok Build. The FBI and CISA issued a joint fact sheet urging critical‑infrastructure owners to enforce least‑privilege access for third‑party industrial‑control‑system integrators. Finally, researchers exposed Russian super‑app MAX’s ability to silently capture screenshots, read and write all mini‑app storage, and inject JavaScript, effectively acting as a man‑in‑the‑middle for user interactions.
💡
The convergence of AI‑enhanced malware and insecure default settings in popular developer tools demonstrates a widening attack surface that can compromise both personal finances and corporate codebases, forcing immediate reassessment of security controls.