This isn’t a leak, but…
BREAKING: Nekogram is secretly sending your phone numbers to the developer
The backdoor is hidden in the http://Extra.java
file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace.
More info about the backdoor: https://github.com/Nekogram/Nekogram/issues/336 (locked by Nekogram devs)
To validate this, we made a PoC: an LSPosed module that replaces the bot ID and username to ours so all requests are going to it. That way, we confirmed that the phone numbers are being collected. Every. Login.
The PoC is available here: https://github.com/RomashkaTea/nekogram-proof-of-logging
What should you do?
1. Report the app on Play Store: https://play.google.com/store/apps/details?id=tw.nekomimi.nekogram
2. Report the repository on GitHub: https://github.com/Nekogram/Nekogram
3. Delete the app and stop using unofficial Telegram clients
READ FULL ARTICLE: This article originally appeared on Mystic Leaks
"I'm calling it the threatro-dollar. The US is basically threatening the rest of the world,…
I am hearing from farmers who are confirming — given diesel prices, they are walking…
🚨 BREAKING: OPENAI Has Disclosed That An Unreleased AI Model Added Unauthorized Instructions To Its…
Leo Terrell, Head Of The Anti-Semitism Task Force, Says Free Speech Doesn’t Protect Criticism Of…
Folks in SE Michigan, N. Texas, and Orlando reporting no diesel. Apparently some signs can…
🇮🇱🇺🇸⚡️🇮🇷 Netanyahu on dragging the U.S. into his war: I’ve been dealing with Iran for…
This website uses cookies.