#mobileSecurity

2025-10-27

Threat brief: Android.Backdoor.Baohuo.1.origin — trojanized Telegram X APKs; 58k+ devices; Redis-backed C2; Xposed/mirrors for stealth; targets Brazil & Indonesia.
Immediate actions:
• Block/unmonitored outbound Redis ports (6379/6378) from mobile management networks.
• Hunt for new persistent device sessions with hidden device IDs or missing active session entries.
• Use app-signature verification at install / MDM policy to block unverified APKs.
• Monitor for frequent 3-minute telemetry bursts and unusual clipboard access patterns.
Share indicators & mitigations in the comments and follow TechNadu for deeper TTP analysis and IOC lists.

#ThreatIntel #MobileSecurity #Android #Redis #Xposed #EDR #Hunting #InfoSec

Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control
2025-10-17

Just came across this amazing tool: Beerus Framework

Developed to assist the mobile pentester during the entire process.

Check it out here: t.co/3a1wOTYAwh

#mobilesecurity #PenetrationTesting

Beerus Framework
2025-10-16

Dockerized Android enables fast, customizable mobile cyber-range simulations with Docker—ideal for security testing and research. hackernoon.com/building-smarte #mobilesecurity

Vicious Space ClippyPrometheus@infosec.exchange
2025-10-15

This Secret Tech Tracked World Leaders, a Vatican Enemy, and Maybe You. #surveillance #malware #mobilesecurity #privacy #altamides #zeroday #zeroclick

youtube.com/watch?v=xfWyU5iXJ3I

2025-10-15

🚨 AI-driven scams are on the rise, targeting Gen Z with sextortion, deepfakes, and virtual kidnappings.

📊 Stats:
- 58% of Gen Z targeted
- 28% victimized
- High emotional & reputational impact

💡 Tip: Stop. Test. Opt-out. Prove it.
💬 Share your experiences or tips in the comments & follow @technadu for expert cybersecurity insights.

#CyberSecurity #AI #Deepfakes #Sextortion #GenZ #MobileSecurity #InfoSec #DigitalSafety #OnlineSafety #TechNadu #ThreatIntel

AI
2025-10-15

A new “Pixnapping” attack steals MFA codes pixel by pixel from Android screens — proof that even screenshots can betray secrets. 📸🔐 #MobileSecurity #MFAR

bleepingcomputer.com/news/secu

2025-10-10

Android malware alert: Mobdro Pro IP TV + VPN installs Klopatra banking Trojan, compromising devices and banking credentials.

More info: technadu.com/fake-vpn-spreads-

#AndroidSecurity #CyberSecurity #BankingTrojan #MobileSecurity #VPN #TechNadu

VPN
Offensive Sequenceoffseq@infosec.exchange
2025-10-10

⚠️ CVE-2025-21050 (HIGH): Samsung Mobile devices pre-Oct 2025 SMR let local attackers access contact data across profiles due to improper input validation. Patch when available & limit profile sharing! radar.offseq.com/threat/cve-20 #OffSeq #Samsung #Vuln #MobileSecurity

High threat: CVE-2025-21050: CWE-20: Improper Input Validation in Samsung Mobile Samsung Mobile Devices
emt Technology Distributionemttech
2025-10-10

Smishing Is Phishing Too 📲
Phishing isn’t just in your inbox anymore.
Text messages with suspicious links are on the rise — and one tap can infect your device.

✅ Don’t click unknown links
✅ Block and report suspicious numbers
✅ Enable mobile security tools

Think before you tap.

@emt

2025-10-09

ClayRat is taking Android spyware to a new level—masquerading as trusted apps with fake reviews and a replica Play Store experience. How safe is your next download when the scam hides in plain sight?

thedefendopsdiaries.com/clayra

#androidspyware
#clayrat
#phishing
#malware
#cybersecurity
#telegram
#socialengineering
#mobilesecurity
#infosec

2025-10-08

Well done and thank you and all hail !
@GrapheneOS
#privacy #grapheneOS #mobilesecurity

Screenshot of a Pixel GrapheneOS with 'Your setttings have changed' Tap to see emergency alert settingsEmergency alerts page in GrapheneOS settings showing that Alert settings are no longer greyed out to Allow but are now configurable and various alerts such as 'Presidential alerts' can be switched off.Screenshot of Pixel phone running GrapheneOS showing 'Allow alerts' has been switched off.
2025-10-04

Hundreds of free VPN apps on Android & iOS found exposing data:

- Outdated encryption (Heartbleed CVE-2014-0160)
- TLS bypass → MitM attacks
- GPS tracking & keylogging
- iOS apps missing privacy manifests

Full report: technadu.com/hundreds-of-free-

#CyberSecurity #VPN #MobileSecurity

hundred vpn
2025-10-03

🚨 Android Spyware Alert: ProSpy & ToSpy
ESET has discovered Android spyware campaigns targeting Signal and ToTok users.

These malicious apps, distributed via fake websites, exfiltrate contacts, SMS, media, and device data.

⚠️ Do NOT install apps from unofficial sources! Stay vigilant.
💬 How can mobile users and organizations improve defenses against spyware? Discuss & follow @technadu for cybersecurity alerts.

#ProSpy #ToSpy #AndroidMalware #CyberSecurity #MobileSecurity #SpywareAlert #Privacy #Infosec #ThreatIntel

Android Spyware Alert: ProSpy & ToSpy
bsidesnovabsidesnova
2025-10-01

Become a digital archaeologist! ⛏️ Learn Android static analysis to crack open APKs and expose hidden vulnerabilities, from hardcoded secrets to lazy permissions, before hackers do.

Workshop bsidesnova-2025.sessionize.com
Ticket tinyurl.com/bsidesnova2025tix

Deobfuscate & Dominate: Conquering Android APKs
Lukatanea
2025-09-25

Προσφέρει μέγιστη ασφάλεια για το κινητό η eSIM; Ακόμα και αν χαθεί ή κλαπεί η συσκευή, μπορεί να στείλει την τοποθεσία της και να προστατεύσει τα προσωπικά σου δεδομένα; Μάθε στο παρακάτω άρθρο!
greek-nea.com/giati-to-esim-ei

Endoacusticacellularispia
2025-09-25

🚀 Introducing the Future of Mobile Security: MDP-X by Endoacustica 🛡️

🔹 Stops zero-click attacks before they strike
🔹 Detects malware, phishing, and spyware in real time
🔹 Blocks risky Wi-Fi, DNS hijacking & MITM attacks
🔹 Runs 100% offline with our patented z9™ AI engine

📲 Secure your devices. Safeguard your data. Stay one step ahead.

👉 Request a demo now: forpressrelease.com/forpressre

Secret Service dismantles massive SIM farm. Mobile domain becoming security battleground.
jpmellojr.blogspot.com/2025/09
#MobileSecurity #SIMFarm #NationalSecurity #SecretService

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst