Lukas Stefanko

@LukasStefanko

Malware Reasercher at , Interested in security and Android malware | Blogger. Opinions are my own.

Geregistreerd in december 2014

Tweets

Je hebt @LukasStefanko geblokkeerd

Weet je zeker dat je deze Tweets wilt bekijken? @LukasStefanko wordt niet gedeblokkeerd door Tweets te bekijken.

  1. Vastgemaakte Tweet
    10 mei

    Uninstall these apps! 15 apps with more than 400k+ installs in total found on Google Play. These apps can download additional payload and display + click on "invisible" ads. Everything is hidden from user's view.

    Deze collectie tonen
    Ongedaan maken
  2. 12 uur geleden

    Android scam app with 100K+ installs spreads via WhatsApp and Google Play in 🇮🇳 Once downloaded, user needs to daily click on ads and share it via WhatsApp to receive Rupees. If withdraw limit is reached (3000₹) you wont get paid because you didn't share.

    Ongedaan maken
  3. 28 jun.

    OMG this Password Manager app! If you type incorrect password it prints correct one in logcat output for everyone. With that pass you can enter app with all the user's secrets.

    Ongedaan maken
  4. 28 jun.

    Don't believe Battery Sector Repair apps, they are fake. They use random algorithm to display wrong battery cells without any "battery scan" functionality. After user hits FIX, they change cell color and make user believe battery is repaired.They like to display ads.

    Ongedaan maken
  5. 28 jun.

    This Android Trojan Spy steals literally everything including Chrome cookies(if device is rooted), calendar events and all key taps(keylogger). Spread: 46.101.204. 168:9011/down/SecChat.apk Hash: B7E6A740D8F1229142B5CEBB1C22B8B1 C&C 206.189.42. 61:7100

    Ongedaan maken
  6. 28 jun.

    Adware from Google Play with 1M+ installs requests Device Admin which makes its removal more difficult. App displays ad whenever user unlocks device and lets you play online game. It has more lines of code for pop-up ads than the game functionality.

    Ongedaan maken
  7. 22 jun.

    Don't install "Direkt Hediyeler" app from Google Play, it's Mobile Banking Trojan. After start request user to log into Akbank Direkt bank. 🇹🇷 What it actually does: 🔹Steals Akbank Direkt banking credentials 🔹Can bypass SMS 2FA Found by

    Deze collectie tonen
    Ongedaan maken
  8. 22 jun.

    "Here’s one example that we chased down in SophosLabs" Bad example how from wrote article based on my video and claimed it was their finding.They published blog 6h after I published my video here on Twitter with exactly same app and web page I discovered

    Ongedaan maken
  9. heeft geretweet
    21 jun.

    I'm quoted with and other Android folks in this article on fake/unofficial Android apps. It's a very tough problem, but I feel it's slowly getting better 📈

    Ongedaan maken
  10. 21 jun.

    For a short time there was used URL shortener to download this SMS Trojan. It got 48K+ hits in 7 days.

    Deze collectie tonen
    Ongedaan maken
  11. 21 jun.

    Example how you can get infected by downloading Android app from YouTube video with 130K+ views. This one send SMS to premium rate number and downloads another fake app.

    Deze collectie tonen
    Ongedaan maken
  12. 20 jun.

    SpyMaster Pro (spying software) allows user to install app from hardcoded path "/sdcard/app/app1.apk" via call to *345123#. What if someone changes this APK file as I did?

    Ongedaan maken
  13. heeft geretweet
    19 jun.

    Android dating app with 10M+ installs leaks ladies profiles with their personal info without authentication. So, the question is, are profiles fake or not 🤔.

    Deze collectie tonen
    Ongedaan maken
  14. 19 jun.

    This guy sells his Android RAT source code for 650$! Offers: support channel, video tutorials and even testing sample. Developed in C# and active since 2017. Unfortunately (for him) it was probably leaked.

    Ongedaan maken
  15. 19 jun.

    my bad, *1M+

    Deze collectie tonen
    Ongedaan maken
  16. 19 jun.

    Android dating app with 10M+ installs leaks ladies profiles with their personal info without authentication. So, the question is, are profiles fake or not 🤔.

    Deze collectie tonen
    Ongedaan maken
  17. heeft geretweet
    19 jun.
    Ongedaan maken
  18. heeft geretweet
    18 jun.
    Ongedaan maken
  19. heeft geretweet
    13 jun.

    [BLOG] New Android banking Trojan takes key logging to another level, develops a new way to time overlay attacks on Android 7/8 and is aggressive on your contact list (rm -rf)

    Deze collectie tonen
    Ongedaan maken
  20. 13 jun.

    9 more apps with 130K+ installs based on Play Store

    Deze collectie tonen
    Ongedaan maken
  21. 13 jun.

    Couple of apps from Google Play right after start download payload from Dropbox. Payload display ads + gathers user e-mail and apps installed on the device. Would it be hard to exchange it with different payload? 🤔 Apps have 50K+ installs. thanks to @imessenger10

    Deze collectie tonen
    Ongedaan maken

Het laden lijkt wat langer te duren.

Twitter is mogelijk overbelast of ondervindt een tijdelijke onderbreking. Probeer het opnieuw of bekijk de Twitter-status voor meer informatie.

    Je bent misschien ook geïnteresseerd in

    ·