Android Security & Malware
43.4K subscribers
127 photos
20 videos
7 files
2.7K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: [email protected]
Download Telegram
Media is too big
VIEW IN TELEGRAM
Chat without internet via Bluetooth
It is open-source, private, secure messaging app without needing the internet, that relies on Bluetooth mesh network
Info: https://www.mobile-hacker.com/2025/07/10/offline-encrypted-and-private-messaging-using-new-bitchat-bluetooth-app/
Download the latest app: https://github.com/permissionlesstech/bitchat-android/releases
πŸ‘¨β€πŸ’»13πŸ‘1
Shizuku unlocks advanced functionality on any Android
Using Shizuku app your Android gains ADB (Shell) privileges to remove bloatware, list running processes, open listening ports, view stored Wi-Fi passwords, inspect logcat of other apps, enable/disable specific Android app components etc.
https://www.mobile-hacker.com/2025/07/14/shizuku-unlocking-advanced-android-capabilities-without-root/
❀29πŸ”₯2πŸ‘1
eSIM might not be as safe as you think: researchers hack and clone numbers
https://security-explorations.com/esim-security.html
πŸ‘10❀1πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
Include computers into Bluetooth mesh network for Bitchat app
βœ…οΈ More devices = more nodes
βœ…οΈ Wider communication range https://github.com/kaganisildak/bitchat-python
🌚5❀4πŸ‘2πŸ”₯1
RaspyJack
Turn a Raspberry Pi Zero 2 W + Waveshare 1.44β€³ LCD into a pocket-sized, SharkJack-style network multitool.
Key features:
β€’ Recon: Multi-profile Nmap scans
β€’ Shells: Reverse-shell launcher (pick IP on the fly or use a preset)
β€’ Creds Capture: Responder, ARP MITM + sniff, DNS-spoof phishing
β€’ Loot Viewer: Read Nmap / Responder / DNSSpoof logs on the screen
https://github.com/7h30th3r0n3/Raspyjack
πŸ”₯18❀8
❀9🌚2πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
Sending bitcoin over Bluetooth between Bitchat Android and iPhone. Both have a native cashu ecash wallet built in.
The ecash travels directly from phone to phone. the sender needs no internet. It is instant and untraceable digital cash.
πŸ‘34πŸ‘12🀨7❀4πŸ”₯3😁3⚑1πŸ₯°1πŸ€”1🌚1
Deobfuscating Android Apps with Androidmeda LLM: A Smarter Way to Read Obfuscated Code

βœ…As a bonus, example of deobfuscating Crocodilus Malware
https://www.mobile-hacker.com/2025/07/22/deobfuscating-android-apps-with-androidmeda-a-smarter-way-to-read-obfuscated-code/
❀15πŸ‘5😁3🌚1
Insecure authentication due to missing brute-force protection and runtime manipulation in Two App Studio Journey v5.5.9 for iOS (CVE-2025-41459)
Journey is a journaling app for iOS that stores personal entries and media
https://cirosec.de/en/news/vulnerability-in-two-app-studio-journey/
🌚7❀4