The StrandHogg vulnerability

Promon security researchers have found proof of a dangerous Android vulnerability, dubbed ‘StrandHogg’, that allows real-life malware to pose as legitimate apps, with users unaware they are being targeted. Lookout, a partner of Promon, confirmed that they have identified 36 malicious apps exploiting the vulnerability. Among them were variants of the BankBot banking trojan observed as early as 2017. *During testing, Promon researchers found that all of the 500 most popular apps (as ranked by app intelligence company 42 Matters) are vulnerable to StrandHogg. *All versions of Android affected, incl. Android 10 (note: the permission harvesting exploit is only from Android 6.0 and onwards).
BankBot: one of the most widespread banking trojans around, with dozens of variants and close relatives springing up all the time. BankBot attacks have been detected all over the world, in the U.S., Latin America, Europe and the Asia Pacific region.

South Korea’s ‘AI for All’ Push Gives Free Access to Every Citizen
107031.08.2026, 00:42
Archaeologists just found a 2,500-year-old well in Italy (photo)
117030.08.2026, 16:36
Neptune’s tiny moons may be the wreckage of shattered ancient worlds
486416.08.2026, 19:42
See the Sun like never before with most detailed images yet (video)
940705.08.2026, 21:22
AWS invests $1 billion to embed AI forward deployed engineers with customers
1166502.08.2026, 21:52
CorPower Ocean secures world-first DNV certification for wave energy technology (video)
1451726.07.2026, 18:33
NASA is watching in real-time for the birth of a new island in the southwestern Pacific Ocean (photo)
1334923.07.2026, 23:05
US, China to hold AI talks in September, sources say
1261822.07.2026, 22:34