Privacy Not A Crime
667 subscribers
195 photos
19 videos
233 links
🔐 Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. 🔰
Download Telegram
🥰532👌11
🧠 GLM-5.3 vs. Claude Mythos 5: Open source model uncovers thousands of vulnerabilities

Chinese AI firm Z.ai has unveiled GLM-5.3, and its most striking achievement wasn't winning standard coding benchmarks. Instead, when tasked with auditing real-world open-source repositories, the GLM family of models identified a staggering 2,436 vulnerabilities across 269 projects. This discovery highlights a growing shift where AI is becoming a primary tool for automated security research, potentially outperforming traditional static analysis tools in finding complex logic flaws.

📊 The scale of the discovery

While many AI models are praised for their ability to generate code, GLM-5.3 demonstrated exceptional prowess in breaking it. The audit covered a wide range of popular open-source libraries, revealing critical issues that had gone unnoticed by human maintainers for years. The sheer volume over two thousand distinct flaws suggests that the current pace of software development may be outstripping our ability to manually review security implications.

This capability poses an interesting dynamic in the AI landscape. While Western models focus heavily on alignment and general utility, this Chinese-developed model has carved a niche in aggressive vulnerability scanning. It raises questions about whether future AI safety standards will need to include offensive capabilities as a core requirement for securing the global software supply chain.

🌟 What this means for developers

For the open-source community, this is a double-edged sword. On one hand, having an AI that can instantly flag thousands of bugs accelerates the patching process and strengthens the ecosystem. On the other, it implies that malicious actors could potentially use similar models to scan for zero-day exploits just as quickly. The barrier to finding critical vulnerabilities is lowering, which means the window of exposure for unpatched software is shrinking rapidly.

Developers should anticipate a future where AI-assisted code review becomes mandatory before merging pull requests. Relying solely on human intuition or legacy linting tools may no longer be sufficient against the speed and depth of modern AI auditors.

🐱 Check the available models at GitHub

💸 Chat with the AI right now

😊 If you enjoyed the article share it with your friends and follow us.

#Vulnerabilities
#OpenSource #GLM53 #CyberSecurity #CodeAudit

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🥰15👌3
✅ Fake Chrome update delivers DragonDoll spyware across 26 countries

A malicious update disguised as Google Chrome has infected Android devices in 26 countries, giving attackers near-total control over victims' phones.

The malware, called DragonDoll, uses "special functions" to bypass security measures and steal sensitive data from encrypted messaging apps like Telegram, WhatsApp, and Signal.

🦠 How the infection works

The attack relies on social engineering, tricking users into installing a fake version of the browser. Once installed, DragonDoll doesn't just steal files. It watches screen activity in real-time, intercepts incoming calls, and captures PINs and passwords as people type them. Most worryingly, it targets end-to-end encrypted apps by reading notifications and screen overlays, essentially bypassing the privacy protections users count on for secure chats.

⚡️ Scope and impact

The campaign has spread fast across 26 nations. The sophistication behind DragonDoll points to a well-funded group behind it, possibly state-sponsored or part of a major cybercrime network. Being able to read Signal messages, a platform known for rock-solid security, shows how serious this breach is. The attack happens at the device level, not by breaking the encryption itself.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #AndroidSafety #DragonDoll #PrivacyMatters #SpywareAlert

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🥰17✍41
🤣7👀4✍3
🤩 AI Jail: Secure sandbox for AI agents

Running AI agents comes with risks. They might touch files they shouldn't or access data they were never meant to see. That's where Ai Jail comes in handy. This multi-platform tool creates a controlled environment for AI agents, locking them down so they can only access what you explicitly allow.

💙 How the isolation works

Ai Jail uses built-in operating system features to do its job. On Linux, it leverages bwrap. On macOS, it relies on sandbox-exec. What happens is straightforward: the tool mounts only the directories an agent actually needs for its task.

So when you're testing a code-writing bot or a data-analysis script, that agent literally cannot see files outside its assigned sandbox. It's similar to containerization, but built specifically for the unique risks that come with autonomous AI decision-making.

💡 Why this matters for AI safety

Here's the thing, AI agents are getting smarter, and with that power comes greater potential for problems. A model might accidentally delete important files, pull credentials from your home directory, or reach out to external networks if left unconstrained. Ai Jail tackles this by taking a "deny-by-default" approach.

Developers and security researchers get a reliable way to test how an agent behaves without risking the rest of their machine.

🐱 Check this tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#CyberSecurity #AISafety #OpenSource #DevOps #PrivacyTools

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍4👀4
🤣 Dark web launches MessiahGPT for cyberattacks at just eight dollars a month

A new neural network called MessiahGPT has emerged on the dark web, significantly lowering the barrier to entry for cybercrime. For approximately eight dollars a month, this clandestine service allows users to generate sophisticated attack tools with a single prompt. The creators are even offering the first 50 requests completely free and without registration, making it accessible to anyone with an internet connection.

😘 Democratizing cybercrime for everyone

The implications are stark: you no longer need to be a skilled hacker or possess deep technical knowledge to launch a cyberattack. With MessiahGPT, a user can instantly generate an extortion scheme, create a convincing phishing page, and craft a detailed deception script, all in one go.

This turns complex cyber warfare into a consumer-grade service. Individuals with malicious intent but zero coding skills can now execute high-impact attacks.

Instead of spending weeks learning exploits or buying fragmented tools, criminals can rely on this AI to orchestrate the entire attack vector. This shift suggests a worrying trend where the technical expertise required for severe breaches is becoming obsolete, replaced by simple subscription fees and prompt engineering.

😆 If you enjoyed the article share it with your friends and follow us.

#MessiahGPT #Cybercrime #DarkWeb #AIThreats #Phishing

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀22
Buy us a coffee ☕
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! 🙏
1👀4✍32
This media is not supported in your browser
VIEW IN TELEGRAM
ℹ️ Chart showing the number of artificial intelligence users from 2022 to the present.

▫️ ChatGPT has gone from 99% to 46%
Please open Telegram to view this post
VIEW IN TELEGRAM
👀6✍2😁1
🛶 Deep State: Real-Time submarine tracking

An open-source initiative called Deep State is changing how we visualize global naval activity. The project tracks 292 submarines currently operating across 30+ navies worldwide, offering a level of transparency that was previously unthinkable for underwater military movements.

📱 Interactive OSINT map

The platform is built around a dynamic, real-time interactive map powered by open-source intelligence (OSINT). Instead of relying on classified reports, it pulls together publicly available data to display submarine positions as they are detected.

The system auto-updates every 6 hours, keeping the information fresh and aligned with the ever-changing geopolitical picture.

🐱 Check this tool at GitHub

🔻 Live OSINT map

😊 If you enjoyed the article share it with your friends and follow us.

#Geoint #NavalTracking #OSINT #Submarines #DefenseTech

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍4👀31
👮‍♂️ Police used public GitHub code to crack EncroChat

Users sought perfect anonymity, but ended up with law enforcement watching their conversations in real time. The massive European operation against organized crime received an unexpected technical explanation that turned out to be remarkably straightforward.

📎 The Bad Binder vulnerability

French cyber intelligence exploited a known Android kernel flaw, identified as CVE-2019-2215 and nicknamed "Bad Binder." Rather than developing a sophisticated zero-day exploit, authorities simply adapted proof-of-concept code that was already publicly available on GitHub. The vulnerability allowed attackers to inject arbitrary code into freed memory areas, effectively creating a backdoor into the encrypted messaging platform.

Once deployed on EncroChat handsets, the malware could capture messages and lock-screen PINs instantly. It bypassed the device's self-destruct "panic-wipe" feature and forwarded intercepted data to police servers within seconds. Czech researchers who later reverse-engineered the French malware confirmed it was essentially a repurposed version of open-source code.

⚖️ Legal and ethical implications

This revelation has sparked intense debate about the legality of using publicly available exploit code for surveillance operations. British lawyers argue this disclosure could reignite legal challenges in the UK's Investigatory Powers Tribunal, where cases have been adjourned for over two years awaiting clarity on the hack's methodology.

Critics warn that relying on existing vulnerabilities rather than developing custom tools lowers the barrier to mass surveillance significantly. Supporters, however, contend that targeting criminal organizations using encrypted devices justified the technical approach.

⚡️ Check the mentioned vulnerability here

😊 If you enjoyed the article share it with your friends and follow us.

#EncroChat #CyberSecurity #Privacy #Vulnerability #OpenSource

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍7👀3
📶 Wi-Fi transforms into a free motion sensor without cameras

Comcast has taken a bold step by turning standard Wi-Fi signals into an invisible radar system. The company has integrated the WiFi Motion feature directly into its Xfinity Shield platform, with a public rollout launching in August 2026. The concept is surprisingly simple: the radio waves traveling between a router and a stationary smart speaker act as a proximity sensor. As these waves bounce off moving objects in the room, they distort slightly, and the application instantly alerts users to movement. This means homeowners no longer need to install cameras in every corner to secure their space.

📖 How the technology works and its limitations

While this sounds like futuristic sci-fi, the practical application comes with nuances. Users can adjust sensitivity settings to filter out pets weighing up to 18 kilograms, effectively reducing false alarms. However, the algorithm currently struggles to detect smaller movements, such as those made by young children. Consequently, this technology cannot yet fully replace traditional audio monitors or baby monitors.

From a privacy standpoint, the implications are significant. Although the system does not recognize faces or capture video footage, it creates a detailed log of how people move throughout their homes. While Comcast emphasizes that it does not track individual identities, the terms suggest that data access could be granted to authorities under specific legal conditions. This raises important questions about the extent of passive surveillance embedded in everyday connectivity devices.

🛜 Beyond Wi-Fi: 5G and the next wave of sensing

The shift toward wireless sensing is not limited to home routers. The rollout of 5G networks opens the door to similar scenarios at a much broader scale. 5G uses higher frequency bands (millimeter-wave) and denser antenna arrays (massive MIMO), which makes the signals even more sensitive to environmental changes. This allows cellular infrastructure in densely covered urban areas to detect movement, gestures, and occupancy patterns through channel-state-information analysis.

Several telecommunications companies are already exploring this frontier. Ericsson and AT&T recently demonstrated how existing 5G sites could detect, locate, and track drones in real time. The same radio waves that deliver high-speed internet can also function as a pervasive presence detection system. When combined with edge computing, compatible cell towers can become potential monitoring nodes. The convergence of Wi-Fi and cellular sensing technologies, known as ISAC (Integrated Sensing and Communication), means our connected world is becoming increasingly aware of physical activity, whether we consent to it or not.

🏭 Industry adoption and future standards

The security sector has quickly recognized the potential of this technology. The industry is actively implementing the new IEEE 802.11bf-2025 standard, which was approved by the IEEE Standards Association Board on May 28, 2025. Major players are already investing heavily; for instance, ADT recently acquired the specialized startup Origin Wireless for $170 million to accelerate similar developments. Soon, the home router will evolve from a simple connectivity box into the primary sensor hub for smart homes, blending internet access with environmental awareness.

As Wi-Fi and 5G sensing become ubiquitous, the line between connectivity and surveillance will continue to blur. It is essential to understand what your network knows about your daily life.

😊 Follow us to stay informed about the latest threats and protect yourself.

#WiFiSecurity #HomePrivacy #IoT #Surveillance #CyberSafety

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍6👀42
😤 Discover 1000+ free and open-source alternatives to paid tools

Tired of expensive subscriptions eating into your budget? A new initiative is quietly changing how people access software.

The project nosubscription.org has compiled over 1,000 free and open-source alternatives to popular paid tools, giving users a practical way to escape the subscription trap without sacrificing functionality.

🖥 Navigate your options with ease

What makes the platform stand out is its search engine and categorization system. Need a secure email client? A professional video editor? A full office suite? Everything's organized so you spend less time hunting and more time working. Each tool comes with a detailed breakdown of features, typical use cases, and links straight to official sources, no sketchy third-party downloads.

👛 Beyond cost savings

The move away from subscription models isn't just about saving money. It's also about reclaiming control over your data. Proprietary software often collects more information than users realize, while open-source projects invite community scrutiny. This transparency matters, especially for journalists, activists, and anyone who values privacy.

Some well-known swaps include LibreOffice for word processing, GIMP for photo editing, and Signal for encrypted communications. You'll find dozens of these replacements alongside hundreds of niche tools you might never have discovered otherwise.

🔗 Check the official website

😊 If you enjoyed the article share it with your friends and follow us.

#OpenSource #PrivacyTools #NoSubscription #CyberSecurity #FreeSoftware

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀7✍4👌111
This media is not supported in your browser
VIEW IN TELEGRAM
📰 Weekly Cybersecurity News Roundup

This week was defined by two major incidents: a significant network outage occurred due to an electrical failure in zone M9 (Russia), and globally, Washington authorized private companies to attack foreign networks.

What formally wasn't considered an act of war is now legal. We've gathered the most interesting news of the week in one place so you don't miss anything.

🌐 Global developments

🔹 An electrical failure in zone M9 in Russia took down Reg.ru and thousands of websites, marking the largest network outage in the country in recent times.

🔹 The White House signed a decree that, in essence, legalizes offensive cyber operations by private contractors against foreign networks.

🔹 The State Department sent a letter to 35 countries asking them to define which side of the technological race, American or Chinese, they would position themselves on regarding AI.

🔹 A leak of 500 repositories from Geedge Networks allowed researchers to create a functional copy of the Great Firewall of China.

🔹 New European standards for VPNs, browsers, antivirus software, and routers threaten manufacturers with fines of up to €15 million for unresolved vulnerabilities.

🔹 Google will implement a mandatory one-day pause before installing applications from unverified developers; by 2027, this will affect all certified Android devices.

🛡 Security sphere updates

🔹 Four T-Mobile employees and a pair of common pliers disabled the Chinese group Salt Typhoon from the operator's networks after a campaign affecting 80 countries.

🔹 The United States accused 17 hackers from Iran's Mabna Institute of stealing 31.5 TB of scientific data from 8,000 professor accounts.

🔹 The French tax agency was hacked twice, resulting in the biggest fiscal cyber scandal in the country's history.

🔹 An open link in the source code of the ClarityCheck service revealed photographs of 9 million faces.

🔹 Passwords have definitively lost their value: according to BiZone, the price of new "cookies" to bypass two-factor authentication has increased by 13%.

💬 Share in the comments how your week went and which news surprised you the most.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberSecurity #DataPrivacy #DataBreach #PrivateOps #Threats

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀6✍321
☕️ Code: A treasure trove for programmers

Discovering the right resources can make all the difference in your coding journey, and code.mu has emerged as a hidden gem for developers of all levels. This website packs a punch by offering a comprehensive collection of detailed tutorials and hands-on exercises covering a wide variety of programming languages, all neatly organized in one accessible place.

👩‍🏫 Comprehensive learning in one spot

What sets this platform apart is its clarity. Each tutorial breaks down complex concepts into digestible steps, supported by practical examples that reinforce understanding.

Whether you are just starting out or looking to sharpen your skills in a specific language, the structured approach ensures you can learn efficiently without getting lost in jargon or overly theoretical explanations.

▫️ Extra: Decoding programmer slang

As a unique addition, the site features a dedicated guide to programmer slang and terminology. This is an invaluable resource for anyone who wants to fully grasp conversations in tech chats, understand industry memes, or simply communicate more effectively with colleagues. It bridges the gap between technical knowledge and cultural fluency in the developer community.

🔗 Check out the website

😊 If you enjoyed the article share it with your friends and follow us.

#CodingResources #ProgrammingTips #LearnToCode #DevCommunity #TechEducation

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍911
Forwarded from Pavel Durov (Pavel Durov)
🚨 Two years ago, I was detained in Paris by police for 3 days — the longest they can hold someone before charging them.

In an unprecedented move, French authorities accused the head of a major platform of crimes committed by its users.

That investigation is still ongoing, although it makes less sense with each passing year.

Why?

Because we now have extensive evidence that Telegram was neither worse than other popular platforms at moderation, nor the worst at cooperating with authorities.

So why was Telegram singled out?

Over the last two years, we have seen a pattern emerge in multiple countries: Telegram is quietly pressured to grant political favors — such as illegal censorship or surveillance. When we refuse, local media and “non-governmental” organizations launch orchestrated campaigns portraying Telegram as a cesspool of crime, from child pornography to terrorism.

Our moderation is no worse than that of other major platforms. Yet these campaigns instill the idea that Telegram should be persecuted or restricted.

Suddenly, officials start caring about crime and protecting children — but only on platforms that reject their secret political demands. Platforms that accept such deals get away with almost anything — including literally selling ads promoting child pornography.

Is the French investigation against me political? It certainly fits the pattern we see elsewhere, mostly in authoritarian countries. And it definitely raises questions.

In time, this investigation may itself be investigated — especially now that Macron’s war against free speech is facing pushback. This month, France’s Constitutional Council struck down his social media ban for children under 15 on freedom-of-expression grounds.

In the end, freedom and truth will prevail ✊
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5🤬2👀22
🤖 GrapheneOS expands to new Motorola devices with enhanced security focus

GrapheneOS has shared important updates about its plans beyond Google Pixel phones. The project is now turning its attention to new hardware, focusing on high-end Motorola devices powered by the latest Snapdragon processors. This shift comes from a practical need for better component isolation and built-in security features that are crucial for their hardened operating system.

ℹ️ Why chip choice matters for privacy

The reason behind prioritizing flagship models is straightforward. Modern Snapdragon chips include security features like memory tagging and proper secure elements, which GrapheneOS relies on for its privacy protections. That said, Motorola's 2026 lineup isn't quite there yet on all fronts. For now, the team will roll out support starting with the premium models that already meet their strict hardware standards. More affordable phones will join later once they catch up on security capabilities.

🦢 Foldables and easier development ahead

Here's something worth noting: foldable devices are on the roadmap too, including both book-style tablets and flip designs. What makes this different from the Pixel situation is the collaboration model.

Motorola will handle much of the system adaptation work themselves, reducing the burden that usually falls on the community. With the manufacturer involved from the start, maintaining updates over time should become noticeably smoother.

7️⃣ Seven years of security promised

Every device coming under this new partnership will commit to GrapheneOS's long-term support promise. That means at least seven years of security patches. This kind of commitment is rare in the Android world. But it comes with conditions: budget-friendly models will have to wait until their hardware can match the same protection levels. The team won't compromise just to expand faster.

This expansion represents a pivotal moment for the project, potentially offering a viable alternative for users seeking hardened Android privacy without being locked into the Pixel ecosystem. As the hardware landscape evolves, the focus remains on ensuring that every supported device meets the uncompromising security baseline the project is known for.

😊 If you enjoyed the article share it with your friends and follow us.

#GrapheneOS #PhonePrivacy #OpenSource #Motorola #AndroidSecurity

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
2✍7🥰2👀2211
This media is not supported in the widget
VIEW IN TELEGRAM
2👀8✍75
🔎 QR code scams: How intelligence services hijack your WhatsApp chats

Cyber espionage groups are evolving their tactics, moving away from obvious fake login pages toward a more insidious method that exploits legitimate authentication features. Instead of tricking victims into entering credentials on counterfeit sites, attackers now manipulate users into voluntarily granting access through official Google, Microsoft and WhatsApp mechanisms. This shift makes detection significantly harder for both individuals and security systems.

🔗 The QR code trap in action

The attack begins with a seemingly innocent request. Victims are contacted, often through fake conference invitations or social engineering, and told they need to scan a QR code to join a secure call or access exclusive content. What follows is the critical moment: the QR code displayed is actually a genuine WhatsApp device-linking code generated by the platform itself. When the victim scans it with their phone, they unknowingly authorize an attacker-controlled device to link to their WhatsApp account.
Once linked, the attacker gains full access to the victim's chat history, can read messages in real-time and even intercept audio and video from calls.

WhatsApp shows no warning signs and the connection appears completely legitimate because it uses the official linking protocol. Security researchers note that allowing camera access for such calls essentially hands over recording capabilities directly to cybercriminals.

😊 Beyond WhatsApp: Abusing trusted platforms

This sophisticated approach extends beyond messaging apps. The same threat actors leverage authentic Google OAuth flows and Microsoft login pages to compromise accounts. Victims might receive a convincing invitation to a virtual summit or a security update prompt that redirects them to legitimate-looking login portals.
Because these pages are hosted by the actual service providers, traditional phishing filters often fail to flag them as malicious.

ℹ️ Why this method is so effective

The power of this technique lies in its psychological manipulation. Traditional phishing relies on urgency or fear to make users overlook red flags. This new approach works differently: it asks victims to perform actions they believe are normal and safe. Scanning a QR code to join a meeting, clicking a legitimate OAuth button to verify identity or approving a device link all feel like routine digital tasks. The screens, codes and login interfaces victims see are genuinely real and are simply being abused.

This method also bypasses many standard two-factor authentication protections. Since the victim themselves authorizes the device link or grants OAuth permissions, security systems interpret these as legitimate user actions rather than unauthorized access attempts.

😊 Follow us to stay informed about the latest threats and protect yourself.

#WhatsApp #APT29 #CyberEspionage #QRPhishing #DigitalPrivacy

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍6👀3😈1🦄1
🛍 AliExpress uses silent audio signals to track devices

Online shoppers may not realize it, but visiting AliExpress can trigger a hidden process that analyzes their device's audio subsystem. This technique, known as audio fingerprinting, doesn't involve recording conversations or activating microphones. Instead, the platform generates an inaudible sound signal internally and examines how the browser and hardware process it. The result becomes part of a broader digital profile used to identify users across sessions, even when traditional tracking methods are unavailable.

⚙️ How the silent tracking mechanism works

Investigation revealed that AliExpress creates two independent AudioContext objects through scripts named collina.js and fireyejs.js, hosted within Alibaba's infrastructure under the AWSC directory. These contexts activate even when no audio or video elements exist on the page, no playback occurs, and no multimedia session is running. Technically, the scripts generate a sawtooth wave via an oscillator, route it through an AnalyserNode and ScriptProcessorNode, then connect it to a GainNode set to zero volume before sending it to AudioContext.destination.

Users hear absolutely nothing, yet the browser performs all the necessary audio processing. The unique way each device handles this silent signal helps build a distinctive fingerprint.

🖐 Why audio fingerprinting matters for your privacy

Unlike traditional cookies that can be deleted or blocked with a click, audio-based identification combines subtle hardware and browser variations into a persistent profile. This allows platforms to recognize returning visitors even when standard tracking mechanisms fail. Privacy advocates brought attention to this case, noting that such techniques enable user identification without relying on cookies at all. Interestingly, the whole thing surfaced almost by accident.

AliExpress argues that these measures help distinguish genuine buyers from automated systems, reducing fraud, fake accounts, and review manipulation. However, the technical capabilities collected allow building a device fingerprint far more resistant than a conventional cookie.

🛡 How to protect yourself from silent audio tracking

Switching to a privacy-oriented browser that is completely open source and has enhanced tracking protection enabled is a strong starting point, as these browsers intentionally distort audio context outputs to break fingerprinting attempts. Installing a reputable ad blocker can block the specific scripts responsible for generating these audio contexts. Using private browsing modes when visiting shopping platforms also adds a layer of separation. Finally, stay aware that many large e-commerce sites employ similar multi-layered tracking strategies combining canvas fingerprinting, font enumeration, and network profiling alongside audio analysis.

😊 If you enjoyed the article share it with your friends and follow us.

#AudioFingerprinting #AliExpress #DeviceTracking #BrowserSecurity #Privacy

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
7✍6👀33😈1
🚘 Malware takes over car stereos: Head units silently join a botnet

Your car's multimedia system is starting to look a lot like a regular computer. And like any computer, it carries the same risks. Kaspersky researchers recently uncovered malware hiding inside Android-based automotive head units built with DoFun firmware, quietly turning vehicles into nodes of a proxy botnet. Here's the unsettling part: drivers didn't need to download or tap anything. The infection happened automatically, through the very update mechanism the car was designed to trust.

🦠 How the infection works

The attack chain starts with TWCore, a legitimate system application on DoFun head units. It's supposed to handle analytics data and push software updates. Under normal conditions, TWCore receives instructions from the manufacturer's cloud about which APK files to download and install. But the update schema includes a flag called installNotExists, allowing it to deploy applications that were never present on the device before. Attackers exploited this feature to silently push a malicious dropper called JarService onto connected vehicles. No user prompt, no visible interface, nothing.

JarService is essentially an empty shell. It has no UI and makes no attempt to impersonate a legitimate app. Its sole job is to decrypt embedded payload data stored in XOR-encrypted blocks and launch the next stage: a loader that uses encrypted strings and Java reflection to execute the final component. This final piece connects to a command-and-control server every 90 minutes, sending device information such as model, display resolution, MAC address, and Wi-Fi SSID. The C2 server replies with integer command identifiers that the Trojan maps to specific actions.

☠️ What the malware actually does

The payload supports nine commands, including making HTTP requests, launching URLs in WebView instances, executing JavaScript, altering clipboard data, testing connectivity, and downloading additional modules. One particularly significant command, loadlib2, downloads and launches a reverse-proxy module called zhima. Once active, zhima converts the infected head unit into a traffic relay, allowing operators to route internet activity through the vehicle's connection.

This mirrors how residential proxy botnets work, where compromised endpoints provide geographically diverse egress infrastructure that can be monetized for fraud, scanning, and other malicious activity. Researchers also observed commands consistent with advertising abuse and click-fraud operations. Kaspersky identified seven distinct variants of the payload by trying different version numbers embedded in the file name, ranging from "3.57" up to "3.68".

❔ Who is behind it

Naming patterns, thread names in the code, and extensive infrastructure overlap point to the MoYu Group, a threat actor closely tied to the BADBOX botnet platform first documented by HUMAN Security in 2023. BADBOX has since infected more than one million Android devices worldwide, spanning phones, TVs, set-top boxes, and streaming sticks. Though German authorities disrupted part of the operation in late 2024, individual actors linked to it continue their activities. This campaign represents a clear expansion into automotive platforms.

DoFun, the Hong Kong based vendor supplying infotainment software for aftermarket head units and claiming to serve over 30 million vehicle owners globally, was notified by Kaspersky. The company reported fixing the underlying security issue in an infrastructure update.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CarHacking #Botnet #AndroidMalware #DoFun #Cybersecurity

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍5👀2
Buy us a coffee ☕
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! 🙏
1👌8✍422😁1👀1