Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands

Abused integrations, poisoned WordPress, and ransomware crews still gunning for endpoint sensors, familiar tradecraft, better packaged.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands
Share

Key points

  • Ransomware affiliates are shipping bring-your-own-vulnerable-driver tooling to kill endpoint sensors before encryption runs.
  • Browser engine bugs disclosed this week warrant aggressive patching; CVSS scores shifted after initial publication on several.
  • An Android banking trojan distributed outside Google Play requests accessibility services, SMS interception, device admin, and overlay rendering.
  • Internet-connected smart TVs with stale firmware are being drafted into proxy-for-hire networks.
  • An OpenBSD flaw landed quietly; notable because bugs of this class are rare in that codebase.

Should you worry about the EDR killer trend?

Yes, and the reason is diffusion. Affiliates who couldn't write a driver loader six months ago are now dropping signed-but-vulnerable binaries pulled from public repositories. The technique isn't new; what's changed is the packaging. Capability has moved downward, and that's the part defenders should care about. Our 19 June story "The Gentlemen RaaS Ships an In-House EDR Killer to Affiliates" showed one crew bundling signed-driver abuse with a kill list of roughly 400 security processes as part of its affiliate package, and this week's activity fits the same pattern. Driver allowlist reviews and telemetry coverage of kernel-level events are the practical response.

What is the Android trojan doing?

The dropper hides behind a fake utility app distributed outside Play. Once installed, it requests accessibility services, SMS interception, overlay rendering, and device admin, a permission manifest that reads like a wishlist. TTPs overlap with families previously associated with operators tracked as part of the broader Brazilian and Eastern European mobile-fraud ecosystem, though I'd put that at low-to-medium confidence pending further samples. We've been tracking this space since "Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil" on 28 May, and the lure-and-overlay playbook hasn't changed much. If your MDM doesn't block sideloading on managed Android devices, that's a gap worth closing before the next campaign lands on a corporate handset.

What is the TV botnet actually about?

It's a capability story more than an intent one. Internet-connected smart TVs with stale firmware are being conscripted into proxy networks, the same playbook run against routers and IP cameras for years, now applied to devices with worse patching discipline. Whoever operates the infrastructure is renting it out. The threat to most organisations is indirect: their users' home devices feeding attack infrastructure they'll eventually face from the other side.

Should you worry about the OpenBSD flaw?

Low drama, worth patching. OpenBSD bugs of this class are rare enough to attract harder scrutiny than equivalents elsewhere, and that scrutiny usually produces a clean patch quickly. Apply it and move on.

What should defenders do this week?

Audit OAuth grants in your tenant and revoke anything stale. Push browser updates aggressively, the gap between disclosure and exploitation keeps shrinking, and CVSS rescores after initial publication mean first-day summaries aren't always reliable. Check driver allowlists if you have the telemetry. Review MDM sideloading policy for Android.

The through-line across all of this: none of it required nation-state tooling. Initial access brokers feed affiliates, affiliates feed ransomware operations, and the commodity ecosystem keeps churning. The interesting question for the coming weeks is whether the driver-abuse diffusion we're seeing starts showing up in intrusion sets that previously relied on simpler evasion. Watch the affiliate handoff layer.

© 2026 Threat Vectr