The threat intelligence landscape is often dominated with talks of sophisticated TTPs (tactics, tools, and procedures), zero-day vulnerabilities, and ransomware. While these technical threats are formidable, they are still managed by human beings, and it is the human element that often provides the most critical breakthroughs in attributing these attacks and de-anonymizing the threat actors behind them.
In our latest webinar, โOPSEC Fails: The Secret Weapon for People-Centric OSINTโ,ย Flashpoint was joined by Joshua Richards, founder of OSINT Praxis. Josh shared an intriguing case study where an attackerโs digital breadcrumbs led to a life-saving intervention.ย
Here is how OSINT techniques, leveraged by Flashpointโs expansive data capabilities, can dismantle illegal threat actor campaigns by turning a technical investigation into a human one.
Leveraging OPSEC as a Mindset
In a technical context, OPSEC is a risk management process that identifies seemingly innocuous pieces of information that, when gathered by an adversary, could be pieced together to reveal a larger, sensitive picture.
In the webinar, we break down the OPSEC mindset into three core pillars that every practitioner, and threat actor, must navigate. When these pillars fail, the investigation begins.
Analyzing the Signature: Every human has a digital signature, such as the way they type (stylometry), the times they are active, and the tools they prefer.
Identity Masking & Persona Management: This involves ensuring that your investigative identity has zero overlap with your real life. A common failure includes using the same browser for personal use and investigative research, which allows cookies to bridge the two identities.
Traffic Obfuscation: Even with a VPN, certain behaviors such as posting on a dark web forum and then using that same connection to check personal banking can expose an IP address, linking it to a practitioner or threat actor.
โEffective OPSEC isnโt about the tools you use; itโs about what breadcrumbs you are leaving behind that hackers, investigation subjects, or literally anyone could find about you.โ
Joshua Richards, founder of Osint Praxis
Leveraging the Mindset for CTI
Understanding the OPSEC mindset allows security teams to think like the target. When we know the psychological traps attackers fall in, we know exactly where to look for their mistakes.
Assumption
The Mindset Trap
The Investigative Reality
Insignificant
โIโm not a high-value target; no one is looking for me.โ
Automated Aggression: Hackers use scripts to scan millions of accounts. You arenโt โchosenโ; you are โdiscoveredโ via automation.
Invisible
โI donโt have a LinkedIn or X account, so I donโt have a footprint.โ
Shadow Data: Public birth records, property taxes, and historical data breaches create a footprint you didnโt even build yourself.
Invincible
โI have 2FA and complex passwords; Iโm unhackable.โ
Session Hijacking: Infostealer malware steals โsession tokensโ (cookies). This allows an actor to be you in a browser without ever needing your 2FA code.
During the webinar, Joshua shares a masterclass in how leveraging these concepts can turn a vague dark web threat into a real-world arrest. Check out the on-demand webinar to see exactly how the investigation started on Torum, a dark web forum, and ended with an arrest that saved the lives of two individuals.
Turn the Tables Using Flashpoint
The insights shared in this session powerfully illustrate that even the most dangerous threat actors are rarely as anonymous as they believe. Their downfall isnโt usually a failure of their technical prowess, but a failure of their mindset. By understanding these OSINT techniques, intelligence practitioners can transform a sea of digital noise into a clear path toward attribution.
The most effective way to dismantle threats is to bridge the gap between technical indicators and human behavior. Whether your teams are conducting high-stakes OSINT or protecting your own organizationโs digital footprint, every breadcrumb counts. By leveraging Flashpointโs expansive threat intelligence collections and real-time data, you can stay one step ahead of adversaries. Request a demo to learn more.
Outbound Email Security Matters for Deliverability and Routing. Especially for organizations that need to deliver a large set of emails, and frequently (Transactional Emails) regarding, for instance, transaction receipts and payment notifications.
Hear a tale about the time the BHIS SOC team conducted a 14-hour overnight incident response... from the Wild West Hackin' Fest conference in Deadwood, South Dakota.
The year 2025 saw a record-breaking number of attacks on Android devices. Scammers are currently riding a few major waves: the hype surrounding AI apps, the urge to bypass site blocks or age checks, the hunt for a bargain on a new smartphone, the ubiquity of mobile banking, and, of course, the popularity of NFC. Letโs break down the primary threats of 2025โ2026, and figure out how to keep your Android device safe in this new landscape.
Sideloading
Malicious installation packages (APK files) have always been the Final Boss among Android threats, despite Googleโs multi-year efforts to fortify the OS. By using sideloading โ installing an app via an APK file instead of grabbing it from the official store โ users can install pretty much anything, including straight-up malware. And neither the rollout of Google Play Protect, nor the various permission restrictions for shady apps have managed to put a dent in the scale of the problem.
According to preliminary data from Kaspersky for 2025, the number of detected Android threats grew almost by half. In the third quarter alone, detections jumped by 38% compared to the second. In certain niches, like Trojan bankers, the growth was even more aggressive. In Russia alone, the notorious Mamont banker attacked 36 times more users than it did the previous year, while globally this entire category saw a nearly fourfold increase.
Today, bad actors primarily distribute malware via messaging apps by sliding malicious files into DMs and group chats. The installation file usually sports an enticing name (think โparty_pics.jpg.apkโ or โclearance_sale_catalog.apkโ), accompanied by a message โhelpfullyโ explaining how to install the package while bypassing the OS restrictions and security warnings.
Once a new device is infected, the malware often spams itself to everyone in the victimโs contact list.
Search engine spam and email campaigns are also trending, luring users to sites that look exactly like an official app store. There, theyโre prompted to download the โlatest helpful appโ, such as an AI assistant. In reality, instead of an installation from an official app store, the user ends up downloading an APK package. A prime example of these tactics is the ClayRat Android Trojan, which uses a mix of all these techniques to target Russian users. It spreads through groups and fake websites, blasts itself to the victimโs contacts via SMS, and then proceeds to steal the victimโs chat logs and call history; it even goes as far as snapping photos of the owner using the front-facing camera. In just three months, over 600 distinct ClayRat builds have surfaced.
The scale of the disaster is so massive that Google even announced an upcoming ban on distributing apps from unknown developers starting in 2026. However, after a couple of months of pushback from the dev community, the company pivoted to a softer approach: unsigned apps will likely only be installable via some kind of superuser mode. As a result, we can expect scammers to simply update their how-to guides with instructions on how to toggle that mode on.
Once an Android device is compromised, hackers can skip the middleman to steal the victimโs money directly thanks to the massive popularity of mobile payments. In the third quarter of 2025 alone, over 44ย 000 of these attacks were detected in Russia alone โ a 50% jump from the previous quarter.
There are two main scams currently in play: direct and reverse NFC exploits.
Direct NFC relay is when a scammer contacts the victim via a messaging app and convinces them to download an app โ supposedly to โverify their identityโ with their bank. If the victim bites and installs it, theyโre asked to tap their physical bank card against the back of their phone and enter their PIN. And just like that the card data is handed over to the criminals, who can then drain the account or go on a shopping spree.
Reverse NFC relay is a more elaborate scheme. The scammer sends a malicious APK and convinces the victim to set this new app as their primary contactless payment method. The app generates an NFC signal that ATMs recognize as the scammerโs card. The victim is then talked into going to an ATM with their infected phone to deposit cash into a โsecure accountโ. In reality, those funds go straight into the scammerโs pocket.
We break both of these methods down in detail in our post, NFC skimming attacks.
NFC is also being leveraged to cash out cards after their details have been siphoned off through phishing websites. In this scenario, attackers attempt to link the stolen card to a mobile wallet on their own smartphone โ a scheme we covered extensively in NFC carders hide behind Apple Pay and Google Wallet.
The stir over VPNs
In many parts of the world, getting onto certain websites isnโt as simple as it used to be. Some sites are blocked by local internet regulators or ISPs via court orders; others require users to pass an age verification check by showing ID and personal info. In some cases, sites block users from specific countries entirely just to avoid the headache of complying with local laws. Users are constantly trying to bypass these restrictions โand they often end up paying for it with their data or cash.
Many popular tools for bypassing blocks โ especially free ones โ effectively spy on their users. A recent audit revealed that over 20 popular services with a combined total of more than 700 million downloads actively track user location. They also tend to use sketchy encryption at best, which essentially leaves all user data out in the open for third parties to intercept.
The permissions that this category of apps actually requires are a perfect match for intercepting data and manipulating website traffic. Itโs also much easier for scammers to convince a victim to grant administrative privileges to an app responsible for internet access than it is for, say, a game or a music player. We should expect this scheme to only grow in popularity.
Trojan in a box
Even cautious users can fall victim to an infection if they succumb to the urge to save some cash. Throughout 2025, cases were reported worldwide where devices were already carrying a Trojan the moment they were unboxed. Typically, these were either smartphones from obscure manufacturers or knock-offs of famous brands purchased on online marketplaces. But the threat wasnโt limited to just phones; TV boxes, tablets, smart TVs, and even digital photo frames were all found to be at risk.
Itโs still not entirely clear whether the infection happens right on the factory floor or somewhere along the supply chain between the factory and the buyerโs doorstep, but the device is already infected before the first time itโs turned on. Usually, itโs a sophisticated piece of malware called Triada, first identified by Kaspersky analysts back in 2016. Itโs capable of injecting itself into every running app to intercept information: stealing access tokens and passwords for popular messaging apps and social media, hijacking SMS messages (confirmation codes: ouch!), redirecting users to ad-heavy sites, and even running a proxy directly on the phone so attackers can browse the web using the victimโs identity.
Technically, the Trojan is embedded right into the smartphoneโs firmware, and the only way to kill it is to reflash the device with a clean OS. Usually, once you dig into the system, youโll find that the device has far less RAM or storage than advertised โ meaning the firmware is literally lying to the owner to sell a cheap hardware config as something more premium.
Another common pre-installed menace is the BADBOX 2.0 botnet, which also pulls double duty as a proxy and an ad-fraud engine. This one specializes in TV boxes and similar hardware.
How to go on using Android without losing your mind
Despite the growing list of threats, you can still use your Android smartphone safely! You just have to stick to some strict mobile hygiene rules.
Install a comprehensive security solution on all your smartphones. We recommend Kaspersky for Androidย to protect against malware and phishing.
Avoid sideloading apps via APKs whenever you can use an app store instead. A known app store โ even a smaller one โ is always a better bet than a random APK from some random website. If you have no other choice, download APK files only from official company websites, and double-check the URL of the page youโre on. If you arenโt 100% sure what the official site is, donโt just rely on a search engine; check official business directories or at least Wikipedia to verify the correct address.
Read OS warnings carefully during installation. Donโt grant permissions if the requested rights or actions seem illogical or excessive for the app youโre installing.
Under no circumstances should you install apps from links or attachments in chats, emails, or similar communication channels.
Buy smartphones and other electronics from official retailers, and steer clear of brands youโve never heard of. Remember: if a deal seems too good to be true, it almost certainly is.