Harly - a new Trojan discovered on Google Play secretly subscribe users to paid services. It is similar to Joker and dates back to 2020.
https://twitter.com/sh1shk0va/status/1570021797697032197
https://twitter.com/sh1shk0va/status/1570021797697032197
X (formerly Twitter)
Tatyana Shishkova (@sh1shk0va) on X
New Trojans on Google Play that secretly subscribe users to paid services - we called this family Harly. Similar to Joker and dates back to 2020, the current campaign is targeting users in Thailand.
https://t.co/fSKyY62FKD
https://t.co/mHfFJ6aavy
https://t.co/fSKyY62FKD
https://t.co/mHfFJ6aavy
👍11🤔6👏1💯1
Fake Security App Found Abusing Japanese Payment System
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-security-app-found-abusing-japanese-payment-system/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-security-app-found-abusing-japanese-payment-system/
McAfee Blog
Fake Security App Found Abuses Japanese Payment System | McAfee Blog
Authored by SangRyol Ryu and Yukihiro Okutomi McAfee’s Mobile Research team recently analyzed new malware targeting mobile payment users in Japan. The
👍13
The deep links crash course, Part 1: Introduction to deep links
https://medium.com/androiddevelopers/the-deep-links-crash-course-part-1-introduction-to-deep-links-2189e509e269
https://medium.com/androiddevelopers/the-deep-links-crash-course-part-1-introduction-to-deep-links-2189e509e269
Medium
The deep links crash course, Part 1: Introduction to deep links
“What can you do with deep links?” I welcome you to the first installment of the deep links crash course series…
🔥15👍11❤1
The deep links crash course, Part 2: Deep links from Zero to Hero
https://medium.com/androiddevelopers/the-deep-links-crash-course-part2-deep-links-from-zero-to-hero-37f94cc8fb88
https://medium.com/androiddevelopers/the-deep-links-crash-course-part2-deep-links-from-zero-to-hero-37f94cc8fb88
Medium
The deep links crash course, Part2: Deep links from Zero to Hero
In this post, we will take a closer look at different types of deep links.
🔥14👍11🍾5🖕3🍌1
Video reverse engineering series of mobile operating systems, applications, and firmware
https://www.youtube.com/playlist?list=PLkOopkYm0fCV45i_n8z5LSUL3QBXNAP2G
https://www.youtube.com/playlist?list=PLkOopkYm0fCV45i_n8z5LSUL3QBXNAP2G
YouTube
Reversing Shorts
Short videos on reverse engineering mobile operating systems, applications, and firmware. Only real-world examples with free tools :)
👍24👏3❤2
Technical analysis of Hydra Android banking malware
https://muha2xmad.github.io/malware-analysis/hydra/
https://muha2xmad.github.io/malware-analysis/hydra/
muha2xmad
Technical analysis of Hydra android malware
بسم الله الرحمن الرحيم
👍11❤3
How I hacked my car (2021 Hyundai Ioniq SEL)
Part 1: https://programmingwithstyle.com/posts/howihackedmycar/
Part 2: https://programmingwithstyle.com/posts/howihackedmycarpart2/
Part 3: https://programmingwithstyle.com/posts/howihackedmycarpart3/
Part 1: https://programmingwithstyle.com/posts/howihackedmycar/
Part 2: https://programmingwithstyle.com/posts/howihackedmycarpart2/
Part 3: https://programmingwithstyle.com/posts/howihackedmycarpart3/
Programming With Style
How I Hacked my Car
Note: As of 2022/10/25 the information in this series is slightly outdated. See Part 5 for more up to date information.
The Car Last summer I bought a 2021 Hyundai Ioniq SEL. It is a nice fuel-efficient hybrid with a decent amount of features like wireless…
The Car Last summer I bought a 2021 Hyundai Ioniq SEL. It is a nice fuel-efficient hybrid with a decent amount of features like wireless…
👍30🔥2🥰1
Rewards plus: Fake mobile banking rewards apps lure users to install info-stealing RAT on Android devices
https://www.microsoft.com/security/blog/2022/09/21/rewards-plus-fake-mobile-banking-rewards-apps-lure-users-to-install-info-stealing-rat-on-android-devices/
https://www.microsoft.com/security/blog/2022/09/21/rewards-plus-fake-mobile-banking-rewards-apps-lure-users-to-install-info-stealing-rat-on-android-devices/
Microsoft News
Rewards plus: Fake mobile banking rewards apps lure users to install info-stealing RAT on Android devices
A fake mobile banking rewards app delivered through a link in an SMS campaign has been making the rounds, targeting customers of Indian banking institutions. Users who install the mobile app are unknowingly installing an Android malware with remote access…
👍23🔥5❤1
Technical analysis of Ginp Android malware
https://muha2xmad.github.io/malware-analysis/ginp/
https://muha2xmad.github.io/malware-analysis/ginp/
muha2xmad
Technical analysis of Ginp android malware
بسم الله الرحمن الرحيم
👍10❤3
iOS Native Code Obfuscation and Syscall Hooking - part 2
https://www.romainthomas.fr/post/22-09-ios-obfuscation-syscall-hooking/
https://www.romainthomas.fr/post/22-09-ios-obfuscation-syscall-hooking/
Romain Thomas
Part 2 – iOS Native Code Obfuscation and Syscall Hooking | Romain Thomas
This second blog post deals with native code obfuscation and RASP syscall interception
👍13
Basecamp for Android app allowed to trigger Javanoscript interface via WebView that would then provide access to Java native code (Bounty - $1,210)
https://hackerone.com/reports/1343300
https://hackerone.com/reports/1343300
HackerOne
Basecamp disclosed on HackerOne: com.basecamp.bc3 Webview...
It was identified that the android **com.basecamp.bc3 application**, contains a Webview where the loaded URLs are not sanitised properly. As this webview's functionality is extended via javanoscript...
👍8
Vulnerabilities discovered in Android and iOS WhatsApp could have caused remote code execution when receiving a crafted video file (CVE-2022-27492) and remote code execution in an established video call (CVE-2022-36934)
https://www.whatsapp.com/security/advisories/2022/
https://www.whatsapp.com/security/advisories/2022/
WhatsApp.com
WhatsApp Security Advisories 2022
WhatsApp Security Advisories 2022 - List of security fixes for WhatsApp products
👍16😈9😁1🌚1
Mobile App Penetration Testing Cheat Sheet
https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet
https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet
GitHub
GitHub - tanprathan/MobileApp-Pentest-Cheatsheet: The Mobile App Pentest cheat sheet was created to provide concise collection…
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. - tanprathan/MobileApp-Pentest-Chea...
👍27🥰1
[0x04] Reversing Shorts :: Finding and Backtracing Signal Messages on Android
https://youtu.be/oy0mn5CV-ro
https://youtu.be/oy0mn5CV-ro
YouTube
[0x04] Reversing Shorts :: Finding and Backtracing Signal Messages on Android
Tracing and backtracing works quite different on Android when compared to iOS. We'll take a look into how to list all Java classes with Frida, how to trace then, and how to generate a Java backtrace from inside the JVM. With an Android Studio virtual phone…
👍19
Discovered ad fraud scheme called - Scylla - that targeted SKDs in apps available on both Google’s Play Store and Apple’s App Store and generated over 13+ million downloads
https://www.humansecurity.com/learn/blog/poseidons-offspring-charybdis-and-scylla
https://www.humansecurity.com/learn/blog/poseidons-offspring-charybdis-and-scylla
HUMAN Security
Poseidon’s Offspring: Charybdis and Scylla - HUMAN Security
HUMAN's Satori Threat Intelligence and Research Team uncovered a network of 89 Android and iOS apps committing various flavors of ad fraud.
👍7🔥2
Analysis of a 7-year mobile surveillance campaign targeting largest minority in China conducted by Scarlet Mimic hacking group
https://blog.checkpoint.com/2022/09/22/cpr-analyzes-a-7-year-mobile-surveillance-campaign-targeting-largest-minority-in-china/
https://blog.checkpoint.com/2022/09/22/cpr-analyzes-a-7-year-mobile-surveillance-campaign-targeting-largest-minority-in-china/
Check Point Blog
CPR analyzes A 7-year mobile surveillance campaign targeting largest minority in China - Check Point Blog
Highlights: Check Point Research (CPR) examines a long running mobile surveillance campaign, targeting the largest minority in China- the Uyghurs. The
👍7
Technical analysis of Alien Android malware
https://muha2xmad.github.io/malware-analysis/alien/
https://muha2xmad.github.io/malware-analysis/alien/
muha2xmad
Technical analysis of Alien android malware
بسم الله الرحمن الرحيم
👍11❤3
Harly: another Trojan subscriber on Google Play
https://www.kaspersky.com/blog/harly-trojan-subscriber/45573/
https://www.kaspersky.com/blog/harly-trojan-subscriber/45573/
Kaspersky
The Harly Trojan subscriber in Google Play apps
A slew of apps containing the Harly Trojan subscriber have been found on Google Play, adding up to more than 4.8 million downloads. We explain why these apps are dangerous.
👍10❤1
Mitigate security risks in your Android app
https://developer.android.com/topic/security/risks
https://developer.android.com/topic/security/risks
Android Developers
Mitigate security risks in your app | App quality | Android Developers
👍20
A Technical Analysis of Pegasus for Android – Part 2
https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/
https://cybergeeks.tech/a-technical-analysis-of-pegasus-for-android-part-2/
👍26🔥5
Heap buffer overflow in Android 12 Can Cause Chrome Sandbox Escape to system privilege
https://bugs.chromium.org/p/chromium/issues/detail?id=1283640
https://bugs.chromium.org/p/chromium/issues/detail?id=1283640
👍18