Diving Into mobile APT group DONOT's Rabbit Hole
https://community.riskiq.com/article/6f60db72
https://community.riskiq.com/article/6f60db72
Demo of Binance wallet theft using Accessibility services
Demo: https://twitter.com/LukasStefanko/status/1316275015889965056
Research: https://link.springer.com/chapter/10.1007/978-3-030-59817-4_2
Demo: https://twitter.com/LukasStefanko/status/1316275015889965056
Research: https://link.springer.com/chapter/10.1007/978-3-030-59817-4_2
Twitter
Lukas Stefanko
Demo of Binance wallet theft using Accessibility services Android PoC malware misuses accessibility to take control over device to withdraw Bitcoins without any user interaction. Binance swiftly fixed the issue. Research & video by @yonas_leguesse Paper:…
Malicious Mintegral SDK Leaks Data on Android
https://youtu.be/o79R4fr2cho
https://youtu.be/o79R4fr2cho
YouTube
Malicious Mintegral SDK Leaks Data on Android
For more information about SourMint, visit the research page (SourMint Malicious SDK Research - https://snyk.io/research/sour-mint-malicious-sdk/) and the Snyk blog page (SourMint: iOS remote code execution, Android findings, and community response - htt…
Hacking into Android in 32 seconds
https://youtu.be/aOWr6rWhsIs
https://youtu.be/aOWr6rWhsIs
👍1
Forwarded from The Bug Bounty Hunter
Hacking Android Apps with Frida
https://youtu.be/iMNs8YAy6pk
https://youtu.be/iMNs8YAy6pk
YouTube
Hacking Android Apps with Frida
Recording from Meta's security conference 2020 - Enjoy
GravityRAT: The spy returns
The cybercriminals added a spy module to Travel Mate, an Android app for travelers to India, the source code of which is available on Github
https://securelist.com/gravityrat-the-spy-returns/99097/
The cybercriminals added a spy module to Travel Mate, an Android app for travelers to India, the source code of which is available on Github
https://securelist.com/gravityrat-the-spy-returns/99097/
Securelist
GravityRAT: The spy returns
In 2018, researchers at Cisco Talos published a post on the spyware GravityRAT, used to target the Indian armed forces. The Indian Computer Emergency Response Team (CERT-IN) first discovered (the document is currently not available at this link, but is
👍1
Android Mobile Hacking Workshop
VIDEO: https://youtu.be/PMKnPaGWxtg
SLIDES: https://docs.google.com/presentation/d/1gK2vYdvwFn8r8dSawIWRRIF4yDF4qmMY2qEelS1M7rI/edit#slide=id.p
VIDEO: https://youtu.be/PMKnPaGWxtg
SLIDES: https://docs.google.com/presentation/d/1gK2vYdvwFn8r8dSawIWRRIF4yDF4qmMY2qEelS1M7rI/edit#slide=id.p
YouTube
Mobile Hacking Workshop - Community Day
This is the mobile hacking workshop I created for HackerOne's Community Day. Each ctf exercise is for learning purposes only and I don't condone any unethical buffoonery.
Workshop Slides:
https://docs.google.com/presentation/d/1gK2vYdvwFn8r8dSawIWRRI…
Workshop Slides:
https://docs.google.com/presentation/d/1gK2vYdvwFn8r8dSawIWRRI…
👍1
Awesome Android Security
Books, bug bounty, courses, tools, labs, talks, write-ups, cheat sheet, blogs
https://github.com/saeidshirazi/awesome-android-security
Books, bug bounty, courses, tools, labs, talks, write-ups, cheat sheet, blogs
https://github.com/saeidshirazi/awesome-android-security
GitHub
GitHub - saeidshirazi/awesome-android-security: A curated list of Android Security materials and resources For Pentesters and Bug…
A curated list of Android Security materials and resources For Pentesters and Bug Hunters - saeidshirazi/awesome-android-security
Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers (Safari, Yandex for Android, Opera Touch for iOS, UC Browser for Android, Opera Mini Android, RITS Browser and Bolt Browser iOS)
https://www.rafaybaloch.com/2020/10/multiple-address-bar-spoofing-vulnerabilities.html
https://www.rafaybaloch.com/2020/10/multiple-address-bar-spoofing-vulnerabilities.html
Miscellaneous Ramblings of a Cyber Security Researcher
Multiple Address Bar Spoofing Vulnerabilities In Mobile Browsers
Explore expert insights on pentesting/bug bounty hunting on this blog, your go-to resource for cutting-edge web security research.
HID attack against PC with Android
This is HID (Human Interface Device) attack against Windows 10, using Samsung S7 (HID) that downloads and executes Metasploit payload by hijacking its keyboard. The second Android device is running meterpreter listener and once payload is launched, device is owned
https://www.instagram.com/p/CGrXqKxg41l/
This is HID (Human Interface Device) attack against Windows 10, using Samsung S7 (HID) that downloads and executes Metasploit payload by hijacking its keyboard. The second Android device is running meterpreter listener and once payload is launched, device is owned
https://www.instagram.com/p/CGrXqKxg41l/
Instagram
Android Security & Hacking
Hacking PC with Android This is HID (Human Interface Device) attack against Windows 10, using Samsung S7 (HID) that downloads and executes Metasploit payload by hijacking its keyboard. The second Android device is running meterpreter listener and once payload…
New education article: all about attacks on Android implicit intents
https://blog.oversecured.com/Interception-of-Android-implicit-intents/
https://blog.oversecured.com/Interception-of-Android-implicit-intents/
News, Techniques & Guides
Interception of Android implicit intents
Explicit intents have a set receiver (the name of an app package and the class name of a handler component) and can be delivered only to a predetermined component (activity, receiver, service). With implicit intents, only certain
Android arbitrary code execution
Frida noscript that helps to identify potential ACE dynamically
https://github.com/androidmalware/android_frida_noscripts#1-file_existsjs
Frida noscript that helps to identify potential ACE dynamically
https://github.com/androidmalware/android_frida_noscripts#1-file_existsjs
GitHub
GitHub - androidmalware/android_frida_noscripts
Contribute to androidmalware/android_frida_noscripts development by creating an account on GitHub.
Samsung S20 - RCE via Samsung Galaxy Store App
https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/
https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/
Getting remote access to PC with Android via USB
https://youtu.be/PJbqZm73MOc
https://youtu.be/PJbqZm73MOc
Link previews in chat apps can cause serious privacy problems
There were found several cases of apps with vulnerabilities such as: leaking IP addresses, exposing links sent in end-to-end encrypted chats, and unnecessarily downloading gigabytes of data quietly in the background
https://www.mysk.blog/2020/10/25/link-previews/
There were found several cases of apps with vulnerabilities such as: leaking IP addresses, exposing links sent in end-to-end encrypted chats, and unnecessarily downloading gigabytes of data quietly in the background
https://www.mysk.blog/2020/10/25/link-previews/
Mysk Blog – In-Depth Cybersecurity & Mobile App Privacy Research
Link Previews: How a Simple Feature Can Have Privacy and Security Risks
Link previews in chat apps can cause serious privacy problems if not done properly. We found several cases of apps with vulnerabilities such as: leaking IP addresses, exposing links sent in end-to-end encrypted chats, and unnecessarily downloading gigabytes…
On Google Play were found 21 gaming apps that were packed with hidden adware
https://blog.avast.com/new-malware-apps-on-google-play-avast
IoC: https://docs.google.com/spreadsheets/d/1Cu6KVYG6VWWCZMY0A-vXlewXyfm7yd0djQtTzc82cyY/edit#gid=0
https://blog.avast.com/new-malware-apps-on-google-play-avast
IoC: https://docs.google.com/spreadsheets/d/1Cu6KVYG6VWWCZMY0A-vXlewXyfm7yd0djQtTzc82cyY/edit#gid=0
Avast
Another 21 malware apps found on Google Play
Avast has uncovered another set of malicious apps in the Google Play Store. While adware is hidden by design, there are steps each person can take to protect themselves and their families.
Android banking malware grew in Q3 with its detections more than four times compared to Q2
https://www.welivesecurity.com/wp-content/uploads/2020/10/ESET_Threat_Report_Q32020.pdf
https://www.welivesecurity.com/wp-content/uploads/2020/10/ESET_Threat_Report_Q32020.pdf
DoNot Android APT group targets India, Pakistan and the Kashmir crisis
https://blog.talosintelligence.com/2020/10/donot-firestarter.html
https://blog.talosintelligence.com/2020/10/donot-firestarter.html
Cisco Talos Blog
DoNot’s Firestarter abuses Google Firebase Cloud Messaging to spread
By Warren Mercer, Paul Rascagneres and Vitor Ventura.
* The newly discovered Firestarter malware uses Google Firebase Cloud Messaging to notify its authors of the final payload location.
* Even if the command and control (C2) is taken down, the DoNot team…
* The newly discovered Firestarter malware uses Google Firebase Cloud Messaging to notify its authors of the final payload location.
* Even if the command and control (C2) is taken down, the DoNot team…
How to monitor Wi-Fi networks using Samsung S7 (link with tutorial, how to install NetHunter, prerequisites, wifi adapter support list, ROM)
https://www.instagram.com/reel/CHF3snlAOOa/
https://www.instagram.com/reel/CHF3snlAOOa/
👏1
Lockscreen and Authentication Improvements in Android 11
https://security.googleblog.com/2020/09/lockscreen-and-authentication.html
https://security.googleblog.com/2020/09/lockscreen-and-authentication.html
Google Online Security Blog
Lockscreen and Authentication Improvements in Android 11
Posted by Haining Chen, Vishwath Mohan, Kevin Chyn and Liz Louis, Android Security Team [Cross-posted from the Android Developers Blog ] ...