In Nekogram, an alternative Telegram client for Android, I recently found a backdoor that leaks the phone number-to-Telegram account mapping to the developer. It also leaks the connection between accounts if there are multiple accounts.
The backdoor is hidden in the file Extra.java, which differs from the template uploaded to the repository. The obfuscated code sends the data as an inline request to the bot @nekonotificationbot, leaving no trace.
I don't understand the developer's motivation. The same file also implements account matching through the bots @tgdb_search_bot and @usinfobot—perhaps the leaked data is used to populate their databases.
I'd like to point out that this isn't the developer's first drama: in the Chinese Telegram community, he's known for DDoS attacks, beta tester data deletion, death threats, and sending offensive notifications. Earlier versions of Nekogram only leaked Chinese numbers—perhaps deanonymization was used to delete accounts of Chinese people participating in political chats, as the developer has previously noted.
I strongly advise against using third-party Telegram clients.
Post #70
6.88K
Nekogram is leaking your phone numbers
- 👍 2