en
Feedback
Android Security & Malware

Android Security & Malware

Open in Telegram

πŸ“ˆ Analytical overview of Telegram channel Android Security & Malware

Channel Android Security & Malware (@androidmalware) in the English language segment is an active participant. Currently, the community unites 45 045 subscribers, ranking 2 911 in the Technologies & Applications category and 657 in the USA region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 45 045 subscribers.

According to the latest data from 02 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 256 over the last 30 days and by -20 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 11.71%. Within the first 24 hours after publication, content typically collects 4.24% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 5 277 views. Within the first day, a publication typically gains 1 911 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 15.
  • Thematic interests: Content is focused on key topics such as cve-2025, exploit, rat, trojan, bypass.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œMobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com”

Thanks to the high frequency of updates (latest data received on 03 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

45 045
Subscribers
-2024 hours
-437 days
+25630 days
Posts Archive

Samsung Galaxy S25 pwned Yesterday at Pwn2Own Ken Gannon and Dimitrios Valsamaras used five different bugs to exploit the Sam
Samsung Galaxy S25 pwned Yesterday at Pwn2Own Ken Gannon and Dimitrios Valsamaras used five different bugs to exploit the Samsung Galaxy S25 and earn $50,000

HyperRat – A New Android RAT Sold On Cybercrime Networks https://iverify.io/blog/hyperrat-a-new-android-rat-sold-on-cybercrime-networks

Patching Android ARM64 library initializers for easy Frida instrumentation and debugging https://blog.nviso.eu/2025/10/14/patching-android-arm64-library-initializers-for-easy-frida-instrumentation-and-debugging/

Account takeover in Android app via JavaScript bridge A misconfigured addJavascriptInterface + flawed domain validation + jav
Account takeover in Android app via JavaScript bridge A misconfigured addJavascriptInterface + flawed domain validation + javascript:// trick enabled full cookie exfiltration via WebView. Exploit chain: JSB dispatcher β†’ file access handler β†’ bypass via newline injection. Payload: Delivered via deeplink. Executed JSB call to toBase64. Read Cookies file from app sandbox. Exfiltrated session data via callback. https://tuxplorer.com/posts/account-takeover-via-jsb/

A vulnerability in DuckDuckGo’s Android browser allows file exfiltration via malicious intent:// URLs to gain access to a vic
A vulnerability in DuckDuckGo’s Android browser allows file exfiltration via malicious intent:// URLs to gain access to a victim’s Sync account data such as account credentials and email protection information (CVE-2025-48464) https://tuxplorer.com/posts/dont-leave-me-outdated/

EnFeSTDroid: Ensembled feature selection techniques based Android malware detection https://www.sciencedirect.com/science/article/pii/S0045790625007062

MCGDroid: An Android Malware Classification Method Based on Multi-Feature Class-Call Graph Characterization https://www.sciencedirect.com/science/article/abs/pii/S016740482500402X

0-click vulnerability in Dolby's DDPlus decoder affected Android (CVE-2025-54957) A malformed audio file can trigger an out-o
0-click vulnerability in Dolby's DDPlus decoder affected Android (CVE-2025-54957) A malformed audio file can trigger an out-of-bounds write due to integer overflow in evolution data handlingβ€”leading to memory corruption and crashes. Android decodes audio messages locally, making this exploitable without user interaction. Reproduction: Just send a crafted RCS voice message (dolby_android_crash.mp4) Details: https://project-zero.issues.chromium.org/issues/428075495

New Android BEERUS framework for dynamic analysis & reverse engineering BEERUS brings Frida auto-injection, sandbox exfiltrat
+3
New Android BEERUS framework for dynamic analysis & reverse engineering BEERUS brings Frida auto-injection, sandbox exfiltration, memory dumps, Magisk integration and more for on device app analysis. https://github.com/hakaioffsec/beerus-android

Modern iOS Security Features – A Deep Dive into SPTM, TXM, and Exclaves https://arxiv.org/pdf/2510.09272

GhostBat RAT: Inside the Resurgence of RTO-Themed Android Malware https://cyble.com/blog/ghostbat-rat-inside-the-resurgence-of-rto-themed-android-malware/

APK Tool GUI: GUI for apktool, signapk, zipalign and baksmali utilities https://github.com/AndnixSH/APKToolGUI
APK Tool GUI: GUI for apktool, signapk, zipalign and baksmali utilities https://github.com/AndnixSH/APKToolGUI

New Pixnapping Attack allows any Android app without permissions to leak info displayed by other apps exploiting Android APIs and a hardware side channel (CVE-2025-48561). Pixnapping is not fixed and probably affects all Androids. PoC: Not available yet. Video demonstrates stealing 2FA codes from Google Authenticator.

Android Physical Memory: CVE-2025-21479 Rights Elevation Record https://dawnslab.jd.com/android_gpu_attack_cve_2025_21479/

Patch Diffing CVE-2024-23265: An iOS Kernel Memory Corruption Vulnerability https://8ksec.io/patch-diffing-ios-kernel/

Exploit for a vulnerability in the Nothing Phone 2a/CMF Phone 1 secure boot chain (and possibly other MediaTek devices) Info
Exploit for a vulnerability in the Nothing Phone 2a/CMF Phone 1 secure boot chain (and possibly other MediaTek devices) Info + PoC: https://github.com/R0rt1z2/fenrir