43932
Mobile cybersecurity channel Links: https://linktr.ee/mobilehacker Contact: mobilehackerofficial@gmail.com
Analysis of RCE of Xiaomi C400 camera by exploiting Vulnerability #1 and #3 combined together. Vulnerabilities are not patched!
Vulnerability #1: Xiaomi - miIO Protocol Authentication Bypass
Vulnerability #2: Xiaomi - miIO client cryptographically weak PRNG
Vulnerability #3: miIO client heap buffer overflow
Analysis: https://labs.taszk.io/articles/post/nowyouseemi/
Exploits and jailbreak for Xiaomi Smart Cameras: https://github.com/TaszkSecLabs/xiaomi-c400-pwn
Using the GBL exploit to bootloader unlock the Xiaomi 17 series
https://www.androidauthority.com/qualcomm-snapdragon-8-elite-gbl-exploit-bootloader-unlock-3648651/
BeatBanker: A dual‑mode Android Trojan
https://securelist.com/beatbanker-miner-and-banker/119121/
iOS DYLIB injection tool for non-jailbreak devices with remote sandbox explorer
Blog: testing-guy/dynamic-analysis-of-ios-local-data-storage-on-non-jailbroken-devices-2e1717420af0" rel="nofollow">https://medium.com/@testing-guy/dynamic-analysis-of-ios-local-data-storage-on-non-jailbroken-devices-2e1717420af0
Github: https://github.com/test1ng-guy/iOS-sandbox-explorer
AndroHunter: A comprehensive Android security research toolkit for bug bounty hunters and mobile penetration testers
https://github.com/ynsmroztas/AndroHunter
Mobile malware evolution in 2025
https://securelist.com/mobile-threat-report-2025/119076/
RedAlert Trojan Campaign: Fake Emergency Alert App Spread via SMS Spoofing Israeli Home Front Command
https://www.cloudsek.com/blog/redalert-trojan-campaign-fake-emergency-alert-app-spread-via-sms-spoofing-israeli-home-front-command
Coruna: Inside the Nation-State-Grade iOS Exploit Kit We've Been Tracking
https://iverify.io/blog/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking
areclaw: Android Reverse Engineering CLI Automation Workspace. AI-driven security analysis with Claude Code.
https://github.com/TheQmaks/areclaw
Captures Android network traffic without proxies or certificates
https://github.com/ProxymanApp/atlantis-android
artifacts: CLI toolkit for static triage of suspicious APKs
https://github.com/drego85/artifacts
How Predator spyware defeats iOS recording indicators
https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/
A Step-by-Step Guide to Uncovering Vulnerabilities in a Mobile App
https://ahmadaabdulla.medium.com/a-step-by-step-guide-to-uncovering-vulnerabilities-in-a-mobile-app-5a6b05e6b23b
First‑ever Mobile Hacking Conference, happening next week — fully online and completely free.
I’ve summarized everything you need to know in one place — speakers, talks, CTFs, giveaways, free courses, and more.
https://www.mobile-hacker.com/2026/02/23/the-first-mobile-hacking-conference-is-coming-this-march/
MythDetector: Android app designed to detect presence of Frida in Android apps
https://github.com/arvinjangid/MythDetector
PulseAPK: Cross-Platform GUI for APK Decompilation, Analysis, and Recompilation
https://github.com/deemoun/PulseAPK-Core
PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time
https://zimperium.com/blog/pixrevolution-the-agent-operated-android-trojan-hijacking-brazils-pix-payments-in-real-time
Frida Android Helper: Several commands to facilitate common Android pentesting tasks
https://github.com/secuworm2/frida-android-helper2
TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control
https://www.cyfirma.com/research/taxispy-rat-analysis-of-taxispy-rat-russian-banking-focused-android-malware-with-full-remote-control/
Claude Code skill that automates Android APK decompilation and API endpoint extraction
https://github.com/SimoneAvogadro/android-reverse-engineering-skill
Auto Frida v2.0: all-in-one Android security testing automation toolkit. Connect your device and let Auto Frida handle everything - from Frida installation to intelligent protection detection and bypass script generation
https://github.com/ommirkute/Auto-Frida
🔴 Live: Mobile Hacking Conference | Day 2
https://www.youtube.com/watch?v=CfioCImyo1U
🔴 We’re LIVE! Join the Mobile Hacking Conference Now.
Be part of the live stream and dive into the latest mobile security and hacking research
Join here: https://www.youtube.com/watch?v=yFROPsi6J7Y
1 script to run the virtual iPhone (iOS 26.1), already jailbroken with full bootstrap installed on Mac
https://github.com/34306/vphone-aio
Gadgetinjector: Frida Gadget injector for iOS 17 / iOS 18 IPAs, designed to work with Objection in listen mode
https://github.com/Saurabh221662/GadgetInjector
How to run virtual iOS 26 iPhone on Apple Silicon Macs, built from Apple’s Private Cloud Compute firmware
https://github.com/wh1te4ever/super-tart-vphone-writeup
Android mental health apps are filled with security flaws
https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/
SURXRAT: From ArsinkRAT roots to LLM Module Downloads Signaling Capability Expansion
https://cyble.com/blog/surxrat-downloads-large-llm-module-from-hugging-face/
Intent Redirection in a Samsung Dialer SVE-2025–1217
happyjester80/intent-redirection-in-a-samsung-dialer-duplicate-sve-2025-1217-0160b0d79a74" rel="nofollow">https://medium.com/@happyjester80/intent-redirection-in-a-samsung-dialer-duplicate-sve-2025-1217-0160b0d79a74
Massiv: When your IPTV app terminates your savings
https://www.threatfabric.com/blogs/massiv-when-your-iptv-app-terminates-your-savings