keybox [Aug30].xml
12.4 KB
ποΈ 2026 30 AUG
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β€1
Malware Fkin: Fake Parivahan SMS β "Mparivahan NextGen" (2026 Edition)
Targeted region:
Β· India
How it works:
1. You receive an SMS with a link claiming to be from Parivahan.
2. The link downloads a "Malware Installer" (M-Parivahan) β harmless on its own.
3. The installer silently installs the real malware: "Mparivahan NextGen".
4. After installation, it requests dangerous permissions:
Β· Phone call access
Β· SMS access
Β· Call forwarding
Β· Device Administrator rights
5. Once granted, it displays a legitimate-looking e-challan page (a WebView of echallan.parivahan.gov.in).
6. It then removes itself from the app launcher by modifying the AndroidManifest, hiding its presence.
Β· Installer: com.core.guard.upxgv39
MD5: 4836f2c927d4d402fe523d352d71916b
Β· Payload (Malware): com.veltrix.documents
MD5: d63a0b5aef62541f6e1b8cba96402beb
Β· Encryption Algorithm: Resources confusion + PayloadSecure2026_ProtectionKey
Data extracted from the infected device:
The malware collects and exfiltrates the following device and SIM information:
Β· androidVersion β Android OS version
Β· appVersion β Malware version
Β· battery β Battery percentage
Β· charging β Whether device is charging
Β· clientApp β Malware identifier
Β· cpuArch β CPU architecture
Β· installedAtMs β Timestamp of installation
Β· ip β Public IP address
Β· model β Device model
Β· now_ms β Current timestamp
Β· phone β Phone number (if available)
Β· rootStatus β Whether device is rooted
Β· sdk β Android SDK level
Β· serviceProvider β Mobile network provider
Β· sim1 β SIM 1 details
Β· sim1_carrier β SIM 1 carrier name
Β· sim1_state β SIM 1 state
Β· sim2_state β SIM 2 state
Β· sim_checked_at_ms β Timestamp of SIM check
Β· status β Device status
Β· storageMB β Total storage in MB
β First, revoke device administrator rights if granted (Settings > Security > Device admin apps)
Just remove from the settings. (if you fall for this kind of scam you noobie btw)
Final Message:
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
A new Android malware is spreading via SMS phishing. The attacker sends a link posing as an official Parivahan e-challan notice. The link downloads an APK that installs a hidden backdoor.
Targeted region:
Β· India
How it works:
1. You receive an SMS with a link claiming to be from Parivahan.
2. The link downloads a "Malware Installer" (M-Parivahan) β harmless on its own.
3. The installer silently installs the real malware: "Mparivahan NextGen".
4. After installation, it requests dangerous permissions:
Β· Phone call access
Β· SMS access
Β· Call forwarding
Β· Device Administrator rights
5. Once granted, it displays a legitimate-looking e-challan page (a WebView of echallan.parivahan.gov.in).
6. It then removes itself from the app launcher by modifying the AndroidManifest, hiding its presence.
Technical Stuffs
Β· Installer: com.core.guard.upxgv39
MD5: 4836f2c927d4d402fe523d352d71916b
Β· Payload (Malware): com.veltrix.documents
MD5: d63a0b5aef62541f6e1b8cba96402beb
Β· Encryption Algorithm: Resources confusion + PayloadSecure2026_ProtectionKey
The encryption algorithm used by this malware was found on Chinese hacking forums, indicating a low-skill, copy-paste threat actor.
Data extracted from the infected device:
The malware collects and exfiltrates the following device and SIM information:
Β· androidVersion β Android OS version
Β· appVersion β Malware version
Β· battery β Battery percentage
Β· charging β Whether device is charging
Β· clientApp β Malware identifier
Β· cpuArch β CPU architecture
Β· installedAtMs β Timestamp of installation
Β· ip β Public IP address
Β· model β Device model
Β· now_ms β Current timestamp
Β· phone β Phone number (if available)
Β· rootStatus β Whether device is rooted
Β· sdk β Android SDK level
Β· serviceProvider β Mobile network provider
Β· sim1 β SIM 1 details
Β· sim1_carrier β SIM 1 carrier name
Β· sim1_state β SIM 1 state
Β· sim2_state β SIM 2 state
Β· sim_checked_at_ms β Timestamp of SIM check
Β· status β Device status
Β· storageMB β Total storage in MB
Removal steps:
β First, revoke device administrator rights if granted (Settings > Security > Device admin apps)
Skilled method
Just remove from the settings. (if you fall for this kind of scam you noobie btw)
ADB method
adb uninstall com.core.guard.upxgv39
adb uninstall com.veltrix.documents
Final Message:
Due to his skill issue he left more details hardcorded β Now on LoneMods will take care of. Im a fkin avg guy
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β€2π₯1
Malware Fkin
Evil is online - It will loads his db with what he really wished for. He can't even stop this with rateLimits as well. Rest will take care by Google (in nobody's dream. Fuk Google)
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β€3π₯1
keybox [Sept11].xml
16.9 KB
ποΈ 2026 11 SEPT
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
Publisher: Focus apps
Game names:
How play these games:
Free games aren't free,
Your data pays the bill.
β LoneMods π€
Game names:
Β· My Cruise: Idle ship Tycoon
Β· Brain Out: Can you pass it?
Β· Find Out: Find Hidden Objects!
Β· Brain Out 3 - puzzle games
Β· Case Hunter: Brain funny Case
Β· Brain Find: Can you find it?
Β· Brain Out 2
Β· AR Tattoo: Fantasy & Fun
Β· Old Face & Daily Horoscope
How play these games:
Β· Disable the internet for this game
Β· Use sandBox - if you can.
Free games aren't free,
Your data pays the bill.
β LoneMods π€
π€3
EYEWIND Games Privacy Policy
Data collected:
Bottom line: looks like a data-hungry, ad-monetized policy. Not automatically illegal, but not privacy-friendly.
Attachment: https://t.me/lonemods/685?single
If you still play:
To delete your account:
Policy: https://www.eyewind.com/en/privacy/
β Not legal advice. Ifykyk
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
If you play any EYEWIND game, read this. Their privacy policy, updated October 16, 2025, raises several concerns.
Data collected:
Β· Collects IMEI, MAC, UDID, IDFA, ad ID, and IP address, then labels them βnon-personal.β Under GDPR, many of these are personal data.
Β· May collect Facebook ID, name, gender, location, and friends list.
Β· In-game check-ins, likes, and recommendations can be public to all users.
Β· Vague third-party sharing: partners, contractors, law enforcement, and mergers.
Β· Contradictory: says it will not share personal data with unaffiliated third parties βforever,β but later lists many exceptions.
Β· Data may be transferred to China or Singapore.
Β· No clear retention period; keeps data as long as services run.
Β· Two different privacy emails: privacy@eyewind.com and Privacy@eyewind.cc.
Β· Age 15+; potential issue if the game is marketed to kids.
Bottom line: looks like a data-hungry, ad-monetized policy. Not automatically illegal, but not privacy-friendly.
Attachment: https://t.me/lonemods/685?single
If you still play:
Β· Avoid Facebook or social login.
Β· Deny ad tracking.
Β· Limit app permissions.
Β· Use guest mode if possible.
To delete your account:
Email: privacy@eyewind.com
Subject: Account Deletion Request β [App Name]
Include your user ID or email and game name.
Policy: https://www.eyewind.com/en/privacy/
β Not legal advice. Ifykyk
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
Telegram
Lone Mods
keybox [sept17].xml
5.4 KB
ποΈ 2026 17 SEPT
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
keybox [sept27].xml
4.4 KB
ποΈ 2026 27 SEPT
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
keybox.xml
16.5 KB
ποΈ 2026 02 OCT
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL TWO CHECKS
βοΈ @keyboxxBot
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
YouTube v21.13.164 (@lonemods).zip
201.8 MB
π§© App Name: YouTube
π Version: 21.13.164
βοΈ Update
π Note:
βοΈ Mod Info:
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
π Version: 21.13.164
βοΈ Update
π Note:
Remove the old module and application
βοΈ Mod Info:
- Premium features unlocked
- Ads removed
- Background audio
- Picture-in-Picture
- SponsorBlock support
- Return Dislike support
- Custom playback controls
- AMOLED dark mode
- Shorts disabled
- Default quality selection
- Default speed selection
- Advanced UI tweaks
- DeArrow integration
- Feed customization
- Customisable application name
- Customisable notification icon
- Customisable application icon
- Clean share links
- Settings backup & restore
π Root users only
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
keybox [oct04].xml
16.5 KB
ποΈ 2026 04 OCT
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
serialNumber:
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
serialNumber:
a79a5441679c1f53a92b33686fe1c0f0
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
keybox [oct04].xml
12.8 KB
ποΈ 2026 04 OCT
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
serialNumber:
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅
β PASSED ALL THREE CHECKS
βοΈ @keyboxxBot
serialNumber:
13abb4712f918d2b0c33d276e6ae1466
β΅βββββββββββββββΒ°βΒ°
πͺ Share LoneMods π«§
Β°βΒ°ββββββββββββββββ΅