en
Feedback
Android Security & Malware

Android Security & Malware

Open in Telegram

πŸ“ˆ Analytical overview of Telegram channel Android Security & Malware

Channel Android Security & Malware (@androidmalware) in the English language segment is an active participant. Currently, the community unites 45 047 subscribers, ranking 2 901 in the Technologies & Applications category and 657 in the USA region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 45 047 subscribers.

According to the latest data from 03 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 248 over the last 30 days and by -1 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 11.64%. Within the first 24 hours after publication, content typically collects 4.24% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 5 241 views. Within the first day, a publication typically gains 1 908 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 13.
  • Thematic interests: Content is focused on key topics such as cve-2025, exploit, rat, trojan, bypass.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œMobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com”

Thanks to the high frequency of updates (latest data received on 04 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

45 047
Subscribers
-124 hours
-557 days
+24830 days
Posts Archive
iOS Crypto Heist: iMessage Zero-Click RCE Chain (CVE-2025-31200, CVE-2025-31201) CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025) Info: https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201 PoC exploit: https://www.dropbox.com/scl/fi/oerpnhq1ui3xfswsszfh2/Audio-clip.amr?rlkey=7n54m1o84poezyipxvd2f9slx&e=3&st=b1tkonvr&dl=0

Two spyware strains - ProSpy & ToSpy - masquerade as Signal and ToTok to infect Androids https://www.welivesecurity.com/en/eset-research/new-spyware-campaigns-target-privacy-conscious-android-users-uae/

Attacking telecom: security bugs from 2G to 5G, SMS exploits, and SS7 & Diameter protocols [presentation] https://www.youtube
Attacking telecom: security bugs from 2G to 5G, SMS exploits, and SS7 & Diameter protocols [presentation] https://www.youtube.com/watch?v=364R1SoGGJ4

Phones auto-connecting to "FreeWiFi_Secure" Wi-Fi network leak full IMSI in cleartext during EAP-SIM exchange Anyone nearby w
Phones auto-connecting to "FreeWiFi_Secure" Wi-Fi network leak full IMSI in cleartext during EAP-SIM exchange Anyone nearby with sniffer could capture it β†’ track users, or correlate identities. Fixed pushed disabling FreeWiFi_Secure on legacy boxes starting Oct 1, 2025. https://7h30th3r0n3.fr/the-vulnerability-that-killed-freewifi_secure/

Silent Smishing : The Hidden Abuse of Cellular Router APIs Cellular router’s API was exploited to send malicious SMS messages containing phishing URLs https://blog.sekoia.io/silent-smishing-the-hidden-abuse-of-cellular-router-apis/

Klopatra: exposing a new Android banking trojan operation with roots in Turkey https://www.cleafy.com/cleafy-labs/klopatra-exposing-a-new-android-banking-trojan-operation-with-roots-in-turkey

Security Evaluation Of Android Apps In Budget African Mobile Devices The study examined 1,544 APKs collected from seven Afric
Security Evaluation Of Android Apps In Budget African Mobile Devices The study examined 1,544 APKs collected from seven African smartphones. The analysis revealed that 145 applications (9%) disclose sensitive data, 249 (16%) expose critical components, and many present additional risks: 226 execute privileged or dangerous commands, 79 interact with SMS messages (read, send, or delete), and 33 perform silent installation operations https://arxiv.org/pdf/2509.18800

Analysis of Android DHCSpy operated by the Iranian APT MuddyWater https://shindan.io/blog/dhcspy-discovering-the-iranian-apt-muddywater

Exploring Android Accessibility Malware | Droidcon Italy 2024 https://www.youtube.com/watch?v=xCHW8ql3vi0

Writeup for CVE-2025-24085, an ITW iOS mediaplaybackd vulnerability patched earlier this year https://github.com/b1n4r1b01/n-days/blob/main/CVE-2025-24085/CVE-2025-24085.md

Triggered WhatsApp 0-click on iOS/macOS/iPadOS CVE-2025-55177 arises from missing validation that the [Redacted] message originates from a linked device, enabling specially crafted DNG parsing that triggers CVE-2025-43300. Analysis of Samsung CVE-2025-21043 is also ongoing Source: https://x.com/DarkNavyOrg/status/1972260639101034950

Banker Trojan Targeting Indonesian and Vietnamese Android Users https://dti.domaintools.com/banker-trojan-targeting-indonesian-and-vietnamese-android-users/

Obtain a root shell on Unisoc unpatched devices (CVE-2023-45866) https://github.com/Skorpion96/unisoc-su/tree/main?tab=readme-ov-file

Finding vulnerabilities in the Binder kernel driver through fuzzing https://androidoffsec.withgoogle.com/posts/binder-fuzzing/

CVE-2025-10184 is permission bypass that affects multiple OnePlus devices running OxygenOS 12–15 (NOT FIXED) with PoC This vu
CVE-2025-10184 is permission bypass that affects multiple OnePlus devices running OxygenOS 12–15 (NOT FIXED) with PoC This vulnerability allows any application installed on the device to read SMS/MMS without permission, user interaction, or consent. https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/

Trigger for the integer underflow bug in the HID core subsystem (CVE-2025-38494 and CVE-2025-38495) that leaks 64 KB of OOB m
Trigger for the integer underflow bug in the HID core subsystem (CVE-2025-38494 and CVE-2025-38495) that leaks 64 KB of OOB memory over USB Still works on Pixels and Ubuntus (but the bug is fixed in stable kernels) https://github.com/xairy/kernel-exploits/tree/master/CVE-2025-38494

Automating Android Component Testing with new APK Inspector tool -What are exported components? -Setup and testing APK Inspector -Improve automation and execute ADB commands interactively -Run it on Android -What are Intent Redirection Vulnerabilities? https://www.mobile-hacker.com/2025/09/18/automating-android-app-component-testing-with-new-apk-inspector/

NFC Card Vulnerability Exploitation Leading to Free Top-Up in KioSoft "Stored Value" Unattended Payment Solution (Mifare) CVE-2025-8699 https://sec-consult.com/vulnerability-lab/advisory/nfc-card-vulnerability-exploitation-leading-to-free-top-up-kiosoft-payment-solution/