Android Security & Malware
43.4K subscribers
134 photos
20 videos
7 files
2.77K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: [email protected]
Download Telegram
Lesser-known Tools for Android Application PenTesting

-Magisk + modules
-DisableFlagSecure
-AdbManager
-ProxyDroid
-pidcat
-resize
https://captmeelo.com/pentest/2019/12/30/lesser-known-tools-for-android-pentest.html
CSRF + XSS + SMS spoofing + Android deep link URL redirection

Great example of chaining low impact vulnerabilities in #TikTok to remotely manipulate account content

-delete user video
-upload user video
-make "private" videos "public"
https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/
Joker Trojan Family history by Google

-tracked since 2017
-removed 1.7K unique apps before going public
-SMS fraud then WAP billing (as we know Joker now)
-at peak, 23 different Jokers submitted in one day to Google Play
https://security.googleblog.com/2020/01/pha-family-highlights-bread-and-friends.html
Memory corruption vulnerability in audio processing during a voice call in #WeChat app

Report includes PoC code + steps how to reproduce the bug
https://bugs.chromium.org/p/project-zero/issues/detail?id=1948