Android Security & Malware – Telegram
Android Security & Malware
43.1K subscribers
127 photos
19 videos
7 files
2.68K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: mobilehackerofficial@gmail.com
Download Telegram
JADXecute - plugin for JADX that adds Dynamic Code Execution abilities
With JADXecute, you can dynamically run Java code to modify or print components of the jadx-gui output
https://github.com/LaurieWired/JADXecute
👍16🔥61
Near-Ultrasound Inaudible Trojan (NUIT): Exploit smartphone speaker voice assistants with inaudible sound to perform commands
Paper: https://sites.google.com/view/nuitattack/home
Video demo: https://youtu.be/TUnPFR35AR4
👍15
iMessage and OpenGraph for Fun and Profit
Forge domain name in website preview shared in iMessage app
https://persist.tools/posts/imessage_og.html
👍61
Chinese Pinduoduo app exploited system vulnerabilities to escalate privileges to download and execute backdoors and gain unauthorized access to user data, notifications and files. The app was also removed from Google Play Store.
Original research: https://mp.weixin.qq.com/s/P_EYQxOEupqdU0BJMRqWsw
Context article: https://krebsonsecurity.com/2023/03/google-suspends-chinese-e-commerce-app-pinduoduo-over-malware/
New analysis report: https://github.com/davincifans101/pinduoduo_backdoor_detailed_report/blob/main/report_en.pdf
👍51
MacStealer: Wi-Fi Client Isolation Bypass
MacStealer can test Wi-Fi networks for client isolation bypasses (CVE-2022-47522) to intercept (steal) traffic toward other clients at the MAC layer
https://github.com/vanhoefm/macstealer
👍123🔥2
Moqhao (Shaoye aka XLoader) malware operated by Yanbian group can bypass text-based CAPTCHAs #RoamingMantis
This feature is used in combination with brute-force attacks on wireless router’s web interfaces to compromise routers and perform DNS hijacking attacks.
https://www.telekom.com/en/blog/group/article/moqhao-masters-new-tricks-1031484
👍12😨2🤔1