TGViewer
Channel Public Channel
Android Security & Malware

Android Security & Malware

@androidmalware

Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: mobilehackerofficial@gmail.com
Subscribers
44.7K
Photos
136
Videos
22
Links
2.9K

Showing posts older than #2020 Β· Back to latest

Older Posts 20 shown
Post #2019 8.8K
Post #2017 8.6K
Post #2016 7.46K
In December 2022, Google discovered in-the-wild exploit chain targeting Samsung Android devices used by commercial mobile spyware vendor Variston.
It appears that n-day exploits that were fixed in Google products in 2022 (Chrome), were not fixed yet in Samsung (Samsung browser) and because of that exploited by espionage software in early exploitation stages.
Final stage, describes how attacker achieved execution as system_server (CVE-2023-0266, CVE-2023-26083)
https://googleprojectzero.blogspot.com/2023/09/analyzing-modern-in-wild-android-exploit.html
projectzero.google Analyzing a Modern In-the-wild Android Exploit By Seth Jenkins, Project ZeroIntroductionIn December 2022, Google’s Threat Analysis Group (...
  • ❀ 11
  • πŸ‘ 4
Post #2014 13.4K
Post #2012 9.93K
Android App Pin Security Issue Allows Unauthorized Payments via Google Wallet even with enabled "Require device unlock for NFC" option (CVE-2023-35671)
While in pinned mode, all other apps become temporarily inaccessible, except Google Wallet.
PoC: https://github.com/MrTiz/CVE-2023-35671
GitHub GitHub - MrTiz/CVE-2023-35671: Android App Pin Security Issue Allowing Unauthorized Payments via Google Wallet Android App Pin Security Issue Allowing Unauthorized Payments via Google Wallet - MrTiz/CVE-2023-35671
  • πŸ‘ 7
  • πŸ”₯ 3
  • πŸ€” 3
Post #2008 10.3K
New 0-click exploit chain discovered targeting iOS devices delivers Pegasus Spyware
Exploit chain was capable of compromising iPhones (iOS 16.6) without any user interaction.
The device is compromised just by receiving malicious image in iMessage (CVE-2023-41064, CVE-2023-41061).
➑️ Update your iOS devices
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
The Citizen Lab BLASTPASS Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware while checking the device of an individual employed by a Washington DC-based civil society organization with international offices. We…
  • πŸ”₯ 20
  • πŸ‘ 8
  • ❀ 5
  • 😁 2
  • 🀯 1
  • πŸ† 1
  • πŸ†’ 1
Post #2007 13.3K
Post #2006 8.45K
Post #2001 10.1K
Post #2000 8.36K
Trojanized Signal and Telegram apps were discovered on Google Play and Galaxy Store
Patched Signal is the first documented case of spying on a victim’s Signal communications by secretly autolinking the compromised device to attacker’s Signal device
https://www.welivesecurity.com/en/eset-research/badbazaar-espionage-tool-targets-android-users-trojanized-signal-telegram-apps/
Welivesecurity BadBazaar espionage tool targets Android users via trojanized Signal and Telegram apps ESET research uncovers active campaigns linked to the China-aligned APT group known as GREF that distributing espionage code previously targeting Uyghurs.
  • πŸ‘ 11
Older posts β†’
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’