Android Malware, VOIP Hijacking, Signal Flaws: This Week's Security Roundup
Explore recent security threats including Android malware, VOIP hijacking, Signal's contact discovery flaws, and more in this week's roundup.

A low-cost Android TV streaming device purchased for $30 was found pre-infected with sophisticated malware that had been installed during manufacturing, according to a detailed technical analysis published online.
Security researcher AyaanB documented the findings after examining a device named in joint warnings issued by the FBI and CISA regarding malicious Android-based media players. These devices have previously been linked to botnets used for activities including distributed denial-of-service (DDoS) attacks, ad-click fraud, and the operation of residential proxy networks.
To investigate without allowing the device to communicate externally, the researcher first identified serial port test pads on the hardware. Using a low-voltage serial adapter, they gained access to the bootloader and extracted the device’s entire filesystem via TFTP. The analysis revealed multiple preinstalled app stores and applications inconsistent with the intended use of a set-top box.
The malware was embedded at the system level. It was signed as a system application, stored in the main system partition of the eMMC storage, and granted SELinux exceptions that elevated its privileges to shell access. Multiple launch scripts ensured the malware would persist even if partially removed.
Further examination showed that the malware installed hooks into the Android process-spawning system. As each application launched, the malware injected itself, modifying or monitoring behavior—even in previously uncompromised apps. The techniques and modified functions matched those associated with the Vo1d botnet, which is used for account takeovers, residential proxying, and deceptive “VPN” services.
Additional components detected included tools for ad-click fraud. Hidden browser windows were rendered without visible output, and display overlays were configured to obscure underlying advertisements. Some tools participated in real-time ad auctions, delivering ads that might not be visible to the user. A root-level backdoor was also found, providing remote operators with full system access and the ability to install further malicious tools.
The researcher has published a comprehensive write-up detailing additional aspects of the malware’s operation and exfiltration methods.
In a separate incident, expired domain records in a little-known telephony standard allowed an individual to intercept attempted calls to military installations on three remote territories for five euros.
The e164-arpa scheme, developed in the early 2000s to map telephone numbers directly to DNS records for SIP and VoIP services, was largely abandoned and infrastructure decayed. The researcher noticed that country-level DNS delegations for Saint Helena, Diego Garcia, and Ascension Island were still pointed to expired domains. By registering these domains, the individual gained control over DNS resolution for those regions.
Initial logs showed minimal traffic, and after consulting technical standards bodies and the United Nations, the project was paused. Six months later, logs revealed hundreds of thousands of attempted calls—many destined for military facilities, including one base that had recently been the target of missile strikes. Had the domains remained under the researcher’s control, calls could have been silently redirected to attacker-controlled servers, enabling surveillance and data interception. The domains were subsequently transferred to the UK National Cyber Security Centre.
AliExpress has been found using covert browser fingerprinting techniques that combine multiple methods to uniquely identify users, even when standard tracking is disabled.
One tactic involved playing an inaudible audio waveform on the webpage and measuring variations in the computed output. These variations are influenced by browser type, CPU, audio hardware, and driver versions. The company also collected data through WebGL rendering, WebRTC interactions, screen resolution, and other web platform integrations.
The purpose of the fingerprinting remains unclear. While it may be used for fraud prevention, it could also facilitate tracking users who have disabled cookies. The method came to light after a user reported issues with Bluetooth headphones auto-connecting to the silent audio stream. While some fingerprinting vectors can be blocked using ad blockers or browser privacy settings, many—such as audio processing and WebGL—are difficult to disable without impairing normal browsing.
Signal’s contact discovery system, which allows users to find other app users in their contacts list without exposing the list to Signal itself, was found to contain vulnerabilities in its Intel SGX enclave-based implementation.
The process relies on Intel’s Software Guard Extensions (SGX), a trusted execution environment designed to isolate sensitive computations. Signal uses SGX to process encrypted contact lists and keys in a protected enclave, with the client verifying the enclave’s integrity against known measurements.
Researchers using the V12 AI agent discovered two attack vectors. A malicious host could exploit race conditions by generating page faults and pausing enclave execution, indirectly leaking secret values used to authenticate servers. This would allow an attacker to impersonate Signal servers and expose user contact lists. A second vulnerability allowed manipulation of client connections to the enclave, enabling full code execution within the enclave and direct exfiltration of contact data.
Both issues were reported to Signal and remediated before public disclosure. There is no evidence they were exploited in the wild.
Medical device manufacturer Boston Scientific disclosed in a U.S. Securities and Exchange Commission filing that it suffered a cyberattack affecting operations. The incident caused a drop in the company’s stock price, though few details were provided regarding the scope or nature of the breach. Boston Scientific said it was investigating the matter and working to restore normal operations.
Comments (0)
No comments yet — be the first to weigh in.
Related Coverage
OpenAI’s Black Hat Reveal: Timeline of Cyberattack on Hugging Face
At Black Hat, OpenAI disclosed a detailed timeline of its cyberattack on Hugging Face, with Simon Willison outlining the sequence and tactics used in detail.
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute (AISI) has released a report detailing incidents of artificial intelligence systems exhibiting unsanctioned behavior during cybersecur...
AI Is Learning to Write Genetic Code
Researchers have demonstrated that artificial intelligence can design functional viral genomes, a development that carries both scientific promise and potential...
Friday Squid Blogging: Neon Flying Squid
Researchers have documented an unusual behavior among neon flying squid, a species previously known only to leap from the water, in a rare observation 370 miles...
Most Read
Prince Harry's Failed Legal Battle: A Threat to Press Freedom Unveiled
US Clears Mines from Strait of Hormuz, Warns Iran Against New Placements
Why Blaming Israel for Anti-Semitism is Dangerous and Racist
Far-right Israeli lawmaker destroys Palestinian memorial with sledgehammer