TeleGapper is a black-box dynamic analysis tool for Telegram Mini Apps on Android devices
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
https://github.com/Mobile-IoT-Security-Lab/TeleGapper
GitHub
GitHub - Mobile-IoT-Security-Lab/TeleGapper: Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations
Black Box Dynamic Analysis Telegram Mini App Tool to detect Privacy Policy Violations - Mobile-IoT-Security-Lab/TeleGapper
๐21๐ฅด21๐คฎ5
Hagaseca: Inside a Packed Android RAT Loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
๐34โค11
WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android
https://calif.io/research/weworm
https://calif.io/research/weworm
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
๐ฅ34โค17
RCE in mexc Android app via Bypass URL validation to access the WebView, JS-Bridge with Path Traversal leads to Native-Library Cache Overwrite.
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
https://itis911.github.io/writeups/RCE-Mexc-Andriod-App.html
โค33๐23
Vwork: Weaponized Open-source Software as an Addon for Gigabud
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
Group-IB
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
๐33โค5
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
Zimperium
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
true
โก18โค14๐1
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Zimperium
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
true
โค16๐12โก10
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
https://www.mobile-hacker.com/2026/09/21/turn-a-rooted-android-phone-into-an-nfc-authenticator-and-automation-tool-for-your-pc/
Mobile Hacker
Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC - Mobile Hacker
Do you have an older rooted Android phone sitting unused in a drawer? Instead of leaving it there, you can turn it into a practical NFC reader and USB keyboard for your computer. With a custom Android app (NFC to HID), your phone can read the unique indentationโฆ
๐19โค9๐2
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
https://blog.nns.ee/2026/09/24/oneplus-root/
https://blog.nns.ee/2026/09/24/oneplus-root/
nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
โค14๐ฅ7๐คฃ1
RemControl: AI Built the Overlays. Victims Lose their PINs
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
https://www.group-ib.com/blog/remcontrol-android-banking-trojan/
Group-IB
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
โก5โค2
A native APK and DEX decompiler written in Rust
https://github.com/Ch0pin/rdx
https://github.com/Ch0pin/rdx
GitHub
GitHub - Ch0pin/rdx: A native APK and DEX decompiler written in Rust
A native APK and DEX decompiler written in Rust. Contribute to Ch0pin/rdx development by creating an account on GitHub.
๐ฑ11โค7๐7
apk-reverse: An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis
https://github.com/newliver666/apk-reverse
https://github.com/newliver666/apk-reverse
GitHub
GitHub - newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis
Suitable for Android APK reverse engineering analysis - newliver666/apk-reverse
๐ฉ3โค2๐1