Practical Mobile Traffic Interception
https://medium.com/@justmobilesec/practical-mobile-traffic-interception-1481e33d974e
https://medium.com/@justmobilesec/practical-mobile-traffic-interception-1481e33d974e
Medium
Practical Mobile Traffic Interception
TL;DR#1: The post will discuss a step-by-step guide of how mobile web traffic can be intercepted on current android and ios applicationsโฆ
๐17โค1
Sapsan Terminal: new AIโpowered HID scripting tool that speeds up payload creation and handles the syntax for 15 supported devices (video test)
https://www.mobile-hacker.com/2026/02/03/sapsan-terminal-ai-powered-badusb-script-generator/
https://www.mobile-hacker.com/2026/02/03/sapsan-terminal-ai-powered-badusb-script-generator/
Mobile Hacker
Sapsan Terminal: AI-Powered BadUSB Script Generator - Mobile Hacker
Cybersecurity professionals and enthusiasts often rely on scripting to automate tasks and execute penetration tests efficiently. Writing payloads manually for devices like Rubber Ducky, Evil Crow Cable, or Flipper Zero can be time-consuming and error-prone.โฆ
๐11๐5โค2๐ค1
FIRST Ever Online Mobile Hacking Conference
Free, worldwide online event bringing the mobile security community together for sessions on mobile hacking, AI, malware, forensics, live mobileโfocused CTF with prizes!
When: March 3 and 4, 2026
Register here: https://www.mobilehackinglab.com/mobile-hacking-conference-registration
Free, worldwide online event bringing the mobile security community together for sessions on mobile hacking, AI, malware, forensics, live mobileโfocused CTF with prizes!
When: March 3 and 4, 2026
Register here: https://www.mobilehackinglab.com/mobile-hacking-conference-registration
๐19
Inside a Multi-Stage Android Malware Campaign Leveraging RTO-Themed Social Engineering
https://www.seqrite.com/blog/inside-a-multi-stage-android-malware-campaign-leveraging-rto-themed-social-engineering/
https://www.seqrite.com/blog/inside-a-multi-stage-android-malware-campaign-leveraging-rto-themed-social-engineering/
Seqrite Labs
Inside a Multi-Stage Android Malware Campaign Leveraging RTO-Themed Social Engineering
<p>In recent years, Android malware campaigns in India have increasingly abused the trust associated with government services and official digital platforms. By imitating well-known portals and leveraging social engineering through messaging applicationsโฆ
๐14โค6
MobSF has Stored XSS via Manifest Analysis of uploaded APK (CVE-2026-24490 )
https://github.com/advisories/GHSA-8hf7-h89p-3pqj
https://github.com/advisories/GHSA-8hf7-h89p-3pqj
๐44โค2๐คช2
Understanding and Experimenting with Apple's Pointer Authentication Codes (PAC) on iOS
https://blog.reversesociety.co/blog/2026/pointer-authentication-code-for-ios
https://blog.reversesociety.co/blog/2026/pointer-authentication-code-for-ios
๐13๐4
Android Dynamic Class Dumper โ dump all DEX files from running Android apps using Frida
https://github.com/TheQmaks/clsdumper
https://github.com/TheQmaks/clsdumper
GitHub
GitHub - TheQmaks/clsdumper: Android Dynamic Class Dumper โ dump all DEX files from running Android apps using Frida
Android Dynamic Class Dumper โ dump all DEX files from running Android apps using Frida - TheQmaks/clsdumper
โค20๐7๐ฉ7๐2๐1
IPATool: command line tool that allows to download iOS apps on the App Store
https://github.com/majd/ipatool
https://github.com/majd/ipatool
GitHub
GitHub - majd/ipatool: Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS Appโฆ
Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store - majd/ipatool
โค25๐ฅ6๐คฎ5๐2๐ฉ1
How to install OpenClaw on Android and control it via WhatsApp using automated script
Blog: https://www.mobile-hacker.com/2026/02/11/how-to-install-openclaw-on-an-android-phone-and-control-it-via-whatsapp/
Installer script: https://github.com/androidmalware/OpenClaw_Termux
Blog: https://www.mobile-hacker.com/2026/02/11/how-to-install-openclaw-on-an-android-phone-and-control-it-via-whatsapp/
Installer script: https://github.com/androidmalware/OpenClaw_Termux
GitHub
GitHub - androidmalware/OpenClaw_Termux: How to Install OpenClaw on an Android Phone and Control It via WhatsApp
How to Install OpenClaw on an Android Phone and Control It via WhatsApp - androidmalware/OpenClaw_Termux
๐ฅด17๐10๐6โค3๐ฉ3๐คฃ3๐1
Intro to Android WebViews and deep linksโฆand how to exploit them
https://djini.ai/intro-to-android-webviews-and-deep-links-and-how-to-exploit-them/
https://djini.ai/intro-to-android-webviews-and-deep-links-and-how-to-exploit-them/
Djini.ai
Intro to Android WebViews and deep links...and how to exploit them - Djini.ai
Android WebView is a system component that allows applications to render web content directly inside a native app, and it is one of the most widely used building blocks in the Android ecosystem. At the same time, deep links have become the primary way appsโฆ
๐23โค9๐2๐1
phantom-frida:
Build anti-detection Frida server from source
https://github.com/TheQmaks/phantom-frida
Build anti-detection Frida server from source
https://github.com/TheQmaks/phantom-frida
GitHub
GitHub - TheQmaks/phantom-frida: Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weeklyโฆ
Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names. - TheQmaks/phantom-frida
๐ฅ17๐7โค2๐1๐1
justapk: Download any APK by package name. 6 sources, automatic fallback, Cloudflare bypass. CLI + Python API
https://github.com/TheQmaks/justapk
https://github.com/TheQmaks/justapk
GitHub
GitHub - TheQmaks/justapk: Download any APK by package name. 6 sources, automatic fallback, Cloudflare bypass. CLI + Python API.
Download any APK by package name. 6 sources, automatic fallback, Cloudflare bypass. CLI + Python API. - TheQmaks/justapk
โค16๐7๐3๐1
JEZAIL: Android pentesting toolkit running fully on rooted devices
https://github.com/zahidaz/jezail
https://github.com/zahidaz/jezail
GitHub
GitHub - zahidaz/jezail: Android pentesting toolkit with REST API, web terminal, screen mirroring, Frida, and full device controlโฆ
Android pentesting toolkit with REST API, web terminal, screen mirroring, Frida, and full device control from your rooted device - zahidaz/jezail
๐12โค8๐4
AWAKE: Android Wiki of Attacks, Knowledge & Exploits
https://zahidaz.github.io/awake/
https://zahidaz.github.io/awake/
zahidaz.github.io
AWAKE
Android Wiki of Attacks, Knowledge & Exploits
๐14๐4
Android Runs ELF Files: Everything Else Is Just Layers
https://blog.azzahid.com/posts/android-runs-elf-files-everything-else-is-just-layers/
https://blog.azzahid.com/posts/android-runs-elf-files-everything-else-is-just-layers/
Zahidโs Blog
Android Runs ELF Files: Everything Else Is Just Layers
If youโve ever wondered how apps written in Python, JavaScript, or C++ can run on Android when everyone says โAndroid is for Java and Kotlin,โ youโre asking the right question. The answer isnโt complicated, but it does require understanding what Android actuallyโฆ
๐11๐2๐2
What Is Android Application-Level Virtualization
https://blog.azzahid.com/posts/android-app-virtualization/
https://blog.azzahid.com/posts/android-app-virtualization/
Zahidโs Blog
What Is Android Application-Level Virtualization
Application-level virtualization in Android is an advanced technology that allows users to run multiple instances of the same app on a single device. Essentially, one app acts as a host, creating isolated virtual spaces where guest apps run as if they wereโฆ
๐6๐4๐ฅ1
Deep analysis of a new Keenadu Android botnet (discovered connection between Triada, BADBOX, Vo1d, and Keenadu)
https://securelist.com/keenadu-android-backdoor/118913/
https://securelist.com/keenadu-android-backdoor/118913/
๐9โก2๐ฅฑ2โค1
The first known Android malware to abuse generative AI (Gemini) in its execution flow
https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/
https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/
Welivesecurity
PromptSpy ushers in the era of Android threats using GenAI
ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow.
โค13๐4๐ฅ4๐2
Massiv: When your IPTV app terminates your savings
https://www.threatfabric.com/blogs/massiv-when-your-iptv-app-terminates-your-savings
https://www.threatfabric.com/blogs/massiv-when-your-iptv-app-terminates-your-savings
ThreatFabric
Massiv: When your IPTV app terminates your savings
Massiv is a new Device Takeover (DTO) malware family without direct links to other known threats, masquerading as an IPTV app.
๐คฃ9๐3โก2๐ค1
MythDetector: Android app designed to detect presence of Frida in Android apps
https://github.com/arvinjangid/MythDetector
https://github.com/arvinjangid/MythDetector
GitHub
GitHub - arvinjangid/MythDetector: MythDetector is a lightweight Android application designed to help developers and testers detectโฆ
MythDetector is a lightweight Android application designed to help developers and testers detect presence of Frida in Android apps. - arvinjangid/MythDetector
๐ฉ12๐6๐5๐คก4โก2