ch
Feedback
Android Security & Malware

Android Security & Malware

前往频道在 Telegram

Mobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com

显示更多

📈 Telegram 频道 Android Security & Malware 的分析概览

频道 Android Security & Malware (@androidmalware) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 43 917 名订阅者,在 技术与应用 类别中位列第 3 070,并在 美国 地区排名第 723

📊 受众指标与增长动态

невідомо 创建以来,项目保持高速增长,吸引了 43 917 名订阅者。

根据 18 六月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 192,过去 24 小时变化为 -1,整体触达仍然可观。

  • 认证状态: 未认证
  • 互动率 (ER): 平均受众互动率为 13.11%。内容发布后 24 小时内通常能获得 4.02% 的反应,占订阅者总量。
  • 帖子覆盖: 每篇帖子平均可获得 5 757 次浏览,首日通常累积 1 764 次浏览。
  • 互动与反馈: 受众积极参与,单帖平均反应数为 12
  • 主题关注点: 内容集中在 cve-2025, exploit, rat, trojan, bypass 等核心主题上。

📝 描述与内容策略

作者将该频道定位为表达主观观点的平台:
Mobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com

凭借高频更新(最新数据采集于 19 六月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。

43 917
订阅者
-124 小时
+827
+19230
帖子存档
Unmasking the Godfather - Reverse Engineering the Latest Android Banking Trojan Talk: https://youtu.be/jNQmc2REwFg Slides: https://github.com/LaurieWired/StrangeLoop

Well explained blog on how to find and exploit XSS in Android apps in WebViews and Deep Links https://securityboulevard.com/2023/10/execution-of-arbitrary-javascript-in-android-application/

Get external IP address of the user during Telegram call. Now it works well and returns public instead of local IP https://twitter.com/androidmalware2/status/1711313647576686621

Trigger iOS proximity paring messages from over 50 meters using Android phone The update of the blog explains how to boost transmitted signal from Android nRF Connect app, demonstrates running AppleJuice on iOS17 and using cheap Arduino ESP32 board https://www.mobile-hacker.com/2023/09/07/spoof-ios-devices-with-bluetooth-pairing-messages-using-android/

NetHunter Hacker IX: How to use MANA Toolkit to create Wi-Fi rogue access point and intercept HTTP traffic https://www.mobile-hacker.com/2023/10/05/nethunter-hacker-ix-use-mana-toolkit-to-create-wi-fi-rogue-access-point-and-intercept-traffic/

BADBOX: a firmware backdoored trojan found in 74,000 Chinese Android phones, tablets, and TV boxes in 227 counties and territories There are confirmed 8 devices with backdoors installed — seven TV boxes, the T95, T95Z, T95MAX, X88, Q9, X12PLUS, and MXQ Pro 5G, and a tablet J5-W. BADBOX functionality: -Ad Fraud, -Uses backdoored devices as proxy, -Create fake accounts, -Downloads and runs additional modules. Report: https://www.humansecurity.com/hubfs/HUMAN_Report_BADBOX-and-PEACHPIT.pdf

Analysis of LightSpy mAPT Mobile Payment System Attack attributed to APT-41 group https://www.threatfabric.com/blogs/lightspy-mapt-mobile-payment-system-attack

Android banking trojan Zanubis, first appeared around August 2022, targeting financial institution and cryptocurrency exchange users in Peru Zanubis’s main infection path is through impersonating legitimate Peruvian Android applications and then tricking the user into enabling the Accessibility permissions in order to take full control of the device https://securelist.com/crimeware-report-asmcrypt-loader-lumma-stealer-zanubis-banker/110512/

Use silent SMS messages to track LTE users’ locations https://mandomat.github.io/2023-09-21-localization-with-silent-SMS/

iOS 15 Image Forensics Analysis and Tools Comparison - Processing details and general device information https://blog.digital-forensics.it/2023/09/ios-15-image-forensics-analysis-and.html

How it is possible to get persistent reverse shell from Android app without visible permissions to make device unusable via annoying DoS https://www.mobile-hacker.com/2023/09/27/get-persistent-reverse-shell-from-android-app-without-visible-permissions-to-make-device-unusable/

NVIDIA GeForce Now for Android contains a vulnerability where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution (CVE‑2023‑31014) https://nvidia.custhelp.com/app/answers/detail/a_id/5476

Android Xenomorph Malware Strikes Again: Over 30+ US Banks Now Targeted https://www.threatfabric.com/blogs/xenomorph

Working solution on how to inject system CA certificates in Android 14 https://httptoolkit.com/blog/android-14-install-system-ca-certificate/

0-days exploited by Predator spyware were delivered via man-in-the-middle (MITM) attack and 0-click vulnerability against iOS and Android https://blog.google/threat-analysis-group/0-days-exploited-by-commercial-surveillance-vendor-in-egypt/

"The WebP 0day" - a full technical analysis the recently patched vulnerability in the WebP image library that was exploited in the wild (CVE-2023-4863) https://blog.isosceles.com/the-webp-0day/

How to bypass 5 advanced root detection techniques using Frida https://8ksec.io/advanced-root-detection-bypass-techniques/

Transparent Tribe’s (APT36) Android CapraRAT Mimics YouTube to Hijack Android Phones https://www.sentinelone.com/labs/capratube-transparent-tribes-caprarat-mimics-youtube-to-hijack-android-phones/

In December 2022, Google discovered in-the-wild exploit chain targeting Samsung Android devices used by commercial mobile spyware vendor Variston. It appears that n-day exploits that were fixed in Google products in 2022 (Chrome), were not fixed yet in Samsung (Samsung browser) and because of that exploited by espionage software in early exploitation stages. Final stage, describes how attacker achieved execution as system_server (CVE-2023-0266, CVE-2023-26083) https://googleprojectzero.blogspot.com/2023/09/analyzing-modern-in-wild-android-exploit.html