ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
AI Summary
The article details multiple active cyber threats, including the RemControl Android banking trojan targeting users in Western Europe, the Middle East, and Canada via fake Google Play Store pages distributed through Meta ads. The malware abuses Android Accessibility Services to perform screen streaming, keystroke logging, and remote control, with command-and-control infrastructure dynamically resolved through encrypted Telegram dead-drops. Phishing overlays and operator panels show signs of AI-assisted development, and Russian-language code comments suggest Russian-speaking involvement. The campaign shares infrastructure and tactics with the Medusa UNKN affiliate botnet, indicating a coordinated threat operation.
AI-extracted · verify before operational use