A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.
Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.
Fake Google Play pages and ad-driven traffic
Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.
The domain third-party.com, a common stand-in for external websites in developer documentation and code samples, is now hosting a fake Cloudflare verification page. The page tries to trick Windows users into running malicious PowerShell commands.
Manifold Security spotted the page while reviewing public AI skills and MCP (Model Context Protocol) server documentation that referenced the domain. BleepingComputer later confirmed the findings.
Developers have long used third-party.com the way they use example.com, to represent some arbitrary outside site, API or service. There is one important difference. IANA, the body that manages key internet naming resources, reserves example.com, example.net and example.org for documentation, and they cannot be registered or transferred. third-party.com has no such protection. It is an ordinary registered domain, and whoever owns it decides what it serves.
A newly spotted variant of the MacSync infostealer is using public iCloud calendar events to deliver its next-stage payloads to macOS systems, according to Kaspersky researchers.
MacSync is written in Swift and first appeared in April 2025. It has recently been pushed through ClickFix campaigns, in which victims are tricked into running commands themselves. Those lures posed as Homebrew and as macOS tools for analysing disk space. Kaspersky says earlier versions of MacSync were derived from the AMOS stealer family. Since then, the malware has grown through additional modules.
A fake crypto wallet as bait
The operators rely on social engineering. Besides ClickFix-style attacks, they offer MacSync disguised as free or cracked software, or as brand-new applications.
The US Department of Justice (DOJ) has arrested two senior figures at Oxygen Forensics, a digital forensics and data extraction company whose software was bought by several federal agencies. Prosecutors allege the firm hid that Russian nationals controlled it and that its technology was developed in Russia.
Oxygen sells tools that investigators use to extract and analyze data from mobile devices, cloud services and drones. It competes directly with Cellebrite. Police and intelligence agencies commonly use this kind of software to break into phones. The company reportedly holds close to 10,000 contracts across more than 150 countries.
Its customers included the Department of Defense (DOD) and the Department of Homeland Security (DHS). Within DHS, several branches used Oxygen products:
Check Point has confirmed that attackers are exploiting CVE-2026-85102, a remote code execution (RCE) vulnerability in its Security Gateway product. The flaw sits in the code that handles VPN certificates, and it can be abused without authentication.
The same advisory covers a second exploited bug, CVE-2026-93616. It is a pre-authentication path traversal flaw in the Management web service that can lead to script execution and Java class loading. According to Check Point, attackers have used it as a zero-day since July 23.
Warning from the Netherlands came first
The Security Gateway issue was already on defenders' radar. On September 10, the Nationaal Cyber Security Centrum (NCSC), the Dutch government's national cybersecurity agency, warned about the flaw. It told users to install the available security updates because it expected exploitation soon.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.