❗️ Unofficial Telegram Client Nekogram Transmits Account-Phone Number Links to Developer
An IT expert who analyzed the Nekogram code informed SOTA about a backdoor discovered within the client:
"The backdoor is hidden in the https://t.co/VyGbC7dEe6 file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace. The same file implements account 'doxing' via several bots; it is possible that the leaked data is used to populate their databases."
Additionally, the developer receives information regarding the linkage of accounts if a user has multiple profiles.
The creator of the Nekogram client—presumably a Chinese national named Fan Li—was previously known for conducting DDoS attacks and unethical online behavior (including death threats against acquaintances).
In early versions of the client, de-anonymization was applied only to Chinese phone numbers, which could have been used for political surveillance; however, it is now applied to all users.
Notably, another unofficial Telegram client, "Telega," utilizes VK servers, providing the state with opportunities to monitor correspondence.
Telegram itself has recently implemented an option to warn users if their interlocutor is using an unofficial client of the messenger.
Illustration: Nekogram code fragment
Something nerds don't want to admit: they low-key enjoy the chaos
Yeah, yeah, ransomware is bad, state sponsored threat actors are bad, but deep down when shit hits the fan it is exciting.
Even though it's just a beep boop computer your adrenaline gets pumping
@EugeneSkyfarer@Techjunkie_Aman Orion Store isn’t really an app store; it simply links RSS links to various well-known apps and downloads them, including some that are pirated. Most of these come from official GitHub repositories, and they also build some of their own, like Morphs.
@vyomant@skylermzx GrapheneOS uses Pixels because they're the only devices currently providing the hardware-based security features and updates. Most smartphones don't allow installing another OS or cripple security with one so those don't qualify for those reasons.
@cb7da12@elonmusk I remember they dropped the Onion version a few years back, with no plans to bring it back.
If you want to browse Twitter anonymously, you can use a public Nitter Tor instance.
https://t.co/6YmsnyK8GK