Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AI'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A sophisticated malware-as-a-service platform called 'Flying Eagle' is actively distributing mobile Remote Access Trojan (RAT) builders across China, enabling multiple threat groups to create infostealers targeting victims' financial accounts. This premium-grade offering represents an escalation in commoditized cybercrime tools, lowering the barrier for attackers to deploy banking trojans and cred
AIFlying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
The Flying Eagle Android RAT source code is spreading through criminal Telegram channels, with researchers identifying 170 servers hosting matching control panels and certificates. The malware framework has been linked to a fraudulent Chinese Public Security service application targeting Android users, with capabilities including payment-password theft.
AIRokarolla Android Trojan Levels Up to Full Device Control, Persistence
The Rokarolla Android Trojan has evolved beyond traditional banking fraud to incorporate comprehensive device surveillance and remote control capabilities. The malware is being distributed through fraudulent TikTok and Chrome application downloads, representing a significant escalation in mobile threat sophistication.
AINew Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Zimperium's zLabs has identified Rokarolla, a sophisticated Android banking trojan that targets 217 banking and cryptocurrency applications with 137 remote commands. The malware enables attackers to gain comprehensive control over infected devices, including stealing lock-screen PINs, intercepting SMS messages, manipulating clipboard content to redirect cryptocurrency payments, and disabling Googl
AIAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
ESET has identified a new Android spyware called Asin specifically targeting Arabic-speaking users through deceptive distribution methods. The malware campaigns, detected in early 2025, utilize fake websites impersonating utilities, war-related information sources, and government news platforms to distribute the spyware to unsuspecting victims.
AIWhatsApp, Slack Notifications Could Hijack Google Gemini on Android
Security researchers discovered a critical vulnerability in Google Gemini's Android voice assistant that could be exploited through malicious notifications from popular messaging apps like WhatsApp, Slack, SMS, Signal, Instagram, or Messenger. The flaw would allow attackers to hijack the assistant without requiring any malicious app installation, potentially enabling unauthorized access to connect
DarkSword Malware
DarkSword is a sophisticated, likely government-designed iOS malware exploiting six zero-day vulnerabilities across iOS versions 18.4-18.7, deployed by multiple commercial surveillance vendors and state-sponsored actors since November 2025. The exploit chain has been used in targeted campaigns across Saudi Arabia, Turkey, Malaysia, and Ukraine, deploying three distinct malware families post-compro
