/security /dev ToxicPanda 2.0 commits banking fraud FROM your own phone, using your own session and IP, after tricking you into granting VPN + Accessibility Service access. We checked our corpus for it and five other major Android banking trojan families (Octo, Cerberus, Anubis, Hook, Medusa). Zero hits across 80,000 sampled indicators. Indicators do exist, from Zimperium zLabs. They are also disposable: rotating AWS buckets, runtime-decrypted payload, fraud committed on-device. What catches this instead: the credentials and session material that leak into stealer logs afterward. Writeup: *(https://blog.relayshield.net/toxicpanda-2-android-banking-trojan-corpus-check)*
- 0 replies
- 0 recasts
- 0 reactions
/security /crypto Kraken emailed me Friday about Privy. Privy’s notice was about their analytics vendor, Metabase. Four hops from me to the dashboard my email was in. No funds moved and that is the point. https://blog.relayshield.net/your-wallet-provider-had-a-vendor-and-that-vendor-had-a-dashboard
- 0 replies
- 0 recasts
- 0 reactions
@cryptonomicon /security /crypto /dev The fake meeting page fingerprints your wallets before any malware exists. EIP-6963 discovery, legacy window.ethereum probing, non-EVM globals, plus extension IDs across ten browser variants. Ordinary web APIs on a page you opened yourself. Operators read the result and decide whether you are worth a payload. Then the clipboard trick: the troubleshooting text on screen is not the text that lands in your buffer. Then the implant looks for Telegram Web or Telegram Desktop and takes that session, which sends the next round of invites to your contacts. Opening the link does not drain you. Pasting the command does. That distinction is the whole defense. https://blog.relayshield.net/sender-recognition-is-not-authentication?source=bluenoroff-farcaster
- 0 replies
- 0 recasts
- 0 reactions