Introducing new #Android #malware analysis platform!
Upload APK, detect malware and grab its configuration.
Currently open for trusted researchers only.
https://www.apkdetect.com/
Upload APK, detect malware and grab its configuration.
Currently open for trusted researchers only.
https://www.apkdetect.com/
Fake VPN app found on Google Play can download and install additional apps.
https://twitter.com/m0br3v/status/1166680295023812609?s=19
https://twitter.com/m0br3v/status/1166680295023812609?s=19
Twitter
I.Zhilyakov
Fake VPN client has been found and removed from Google Play. On command: -opens web, #instagram, #telegram and google play pages -downloads and tries to install other applications ioc: d789d13c6187ad3cd2991b6d387d9e943d394a8c #android #trojan #malware
Two spy apps that steal contact list found on Google Play with 110+ installs
https://twitter.com/s_metanka/status/1181192866875559936
https://twitter.com/s_metanka/status/1181192866875559936
Twitter
smtnk
These two young apps on @GooglePlay steal the users' contact lists and leak them all (~3k unique records) via unprotected Firebase instances, mostly UAE/Pakistan/Saudi Arabia victims it seems. #Android #Malware https://t.co/6INCOHBiLE https://t.co/o1mPKjrHNr
New Joker Trojan app with 100,000+ installs found on Google Play
https://twitter.com/s_metanka/status/1181592422796664837
https://twitter.com/s_metanka/status/1181592422796664837
Twitter
smtnk
A new Joker app on @GooglePlay ”Amusing game station" - 100,000+ installs. The loader is slightly improved, the core build is an old s8-7-release. Targets: GR,AT,DE,PK,UAE,BD,TH. Distribution C&C: doocims[.]com, main C&C: 18.139.46[.]15 https://t.co/NXfFLZz6rD…
Clicker for Android subscribes users to paid services #Joker #Malware
https://news.drweb.com/show/?i=13464&lng=en
https://news.drweb.com/show/?i=13464&lng=en
Dr.Web
Clicker for Android subscribes users to paid services
Doctor Web has detected a clicker trojan that can automatically subscribe users to paid services in the official Android app store.
More Joker Trojans on Google Play
8 apps with 196,000+ installs
https://twitter.com/m0br3v/status/1186277973923696641
https://twitter.com/sh1shk0va/status/1186291616769814529
8 apps with 196,000+ installs
https://twitter.com/m0br3v/status/1186277973923696641
https://twitter.com/sh1shk0va/status/1186291616769814529
Twitter
I.Zhilyakov
And more #joker samples: com.billiards.wallpapers - October 18, 2019, 10,000+ com.peculiarwallpaper.wpshow - October 15, 2019, 50,000+ com[.de.sourceforge.opencamera - October 16, 2019, 10,000+ com.zima.latest.gamelist - October 15, 2019, 100,000+ #malware…
What a interesting vulnerability in HockeyApp platform #Android #iOS #BugBounty
Leaked API key allowed:
-fetch internal employee contacts
-distribute #malware directly to devices of organization employees as internal app update
+PoC Metasploit scenario
https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/
Leaked API key allowed:
-fetch internal employee contacts
-distribute #malware directly to devices of organization employees as internal app update
+PoC Metasploit scenario
https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/
allysonomalley.com
Saying Goodbye to my Favorite 5 Minute P1
In this post, I’m going to reveal the fastest, easiest P1 that I’ve ever reported – multiple times! It’s the sort of oversight that seems so simple to avoid, but surprisingl…
Android Malware in COVID-19 Clothes Steals SMS and Contacts
https://labs.bitdefender.com/2020/05/android-malware-in-covid-19-clothes-steals-sms-and-contacts/
https://labs.bitdefender.com/2020/05/android-malware-in-covid-19-clothes-steals-sms-and-contacts/
Bitdefender Labs
Android Malware in COVID-19 Clothes Steals SMS and Contacts
Criminals are using an old certificate to sign a malware that takes advantage of
the COVID-19 pandemic situation, preying on people’s need for information.
the COVID-19 pandemic situation, preying on people’s need for information.
Video demo how Android Spyware steals WhatsApp messages from received notifications
https://www.instagram.com/reel/CFwz9wMAwuL/
https://www.instagram.com/reel/CFwz9wMAwuL/
Instagram
Android Security & Hacking
What happens if you "Allow notification" access to malicious app. Video demo how easy it is for such malicious spyware to steal WhatsApp messages from received notifications . . . . . #hackers #hacking #hacker #cybersecurity #ethicalhacking #hack #kalilinux…