TGViewer
MonoGram MonoGram @monogram_android · 5.74K subscribers
Post #70 55.5K
A phone number-stealing backdoor was found in Nekogram

The malicious code is concealed within Extra.java (notably, the public repo version of this file is clean). It operates by using obfuscated code to send data through an inline query to @nekonotificationbot, leaving almost zero footprint.

Additionally, if several accounts are connected within the app, the developer can easily see that they belong to the same person.


В Nekogram нашли бэкдор, который сливает номера телефонов

Бэкдор спрятан в файле Extra.java (причем в публичном репозитории проекта этот файл выглядит иначе). Схема работает так: обфусцированный код передает данные через inline-запрос боту @nekonotificationbot, практически не оставляя следов.

А если в приложении подключено сразу несколько аккаунтов, разработчик легко узнает, что все они связаны между собой.


The Google Play version also has this malicious code

Версия из Google Play тоже имеет этот вредоносный код


Sources:
1. Nekogram 12.5.2
2. Screenshot by @andreyduhen (Thanks 😏)
  • 🤬 237
  • 👍 18
  • 🔥 12
  • ❤ 9
  • 👏 6
More from @monogram_android
  1. Sep 27, 2026document post
  2. Sep 27, 2026Post #211
  3. Sep 4, 2026Post #210
  4. Sep 4, 2026Post #209
  5. Aug 14, 2026🚨 Hotfix deployed! We've re-uploaded the files to fix a critical issue Please re-download…
  6. Aug 14, 2026document post
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →