hacker-news · Crawled Sep 24, 2026

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

7 IoCs 2 Malware
Read original article ↗

AI Summary

The article details multiple active cyber threats, including the RemControl Android banking trojan targeting users in Western Europe, the Middle East, and Canada via fake Google Play Store pages distributed through Meta ads. The malware abuses Android Accessibility Services to perform screen streaming, keystroke logging, and remote control, with command-and-control infrastructure dynamically resolved through encrypted Telegram dead-drops. Phishing overlays and operator panels show signs of AI-assisted development, and Russian-language code comments suggest Russian-speaking involvement. The campaign shares infrastructure and tactics with the Medusa UNKN affiliate botnet, indicating a coordinated threat operation.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 7 extracted

Type Value Detail
Domain adminmenueditor[.]com Details →
Filename wp-user-consent.php Details →
Package ulid-xyz Details →
Filename dist/node/utils.js Details →
Filename dist/node/payload.js Details →
Package js-logger-pack Details →
Package terminal-logger-utils Details →

MITRE ATT&CK TTPs 9 techniques