News Summary:
On September 30, 2026, Zimperium security researchers uncovered a new Android malware strain, named RedHat, linked to threat actors believed to be operating from China. This malware targets banking credentials, 2FA and OTP codes, notifications, and other sensitive data while providing persistent remote access to compromised devices. Previously, on September 27, agentic AI systems were observed accelerating attacks on mobile applications, automating tasks that once required extensive time and expertise, such as analyzing app defenses and bypassing security controls. This followed Zimperium's identification on September 25 of deceptive Android apps abusing Google Play’s Early Access program. These apps appeared legitimate but directed users toward risky external downloads and services through misleading descriptions and fake functionality. Earlier, on September 24, reports indicated threat actors were exploiting voice calls and texts on personal mobile devices, impersonating IT help desks to steal Microsoft 365 credentials and authentication tokens, thereby bypassing corporate security controls on unmanaged BYOD devices. On September 23, Zimperium released findings detailing how agentic AI is facilitating sophisticated mobile app attacks, with these systems autonomously planning, executing, and refining strategies based on failures.