cross-posted from: https://piefed.world/c/tech/p/1146502/telegram-apk-from-apkpure-is-a-spyware

On analyzing the APK with jadx, it contains a class DataCollector, which does not exist in the .apk file downloaded from the official Telegram website.

This class collects a lot of your data, including:

  • Your photos, videos, and files
  • Your contacts
  • Your messages
  • Your GPS Coordinates
  • Your SIM card information
  • Your Telegram profile

This data is monitored and uploaded continuously. All the data is uploaded to a server with IP Address 38.190.225.166

💬 Initial discovery by Eric Parker

🔗 APK Analysis: Part 1 | Part 2.

Source on Telegram.

    • Staff@piefed.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      3 days ago

      Forkgram is kinda sus in my phone. It’s always opening notifications. Sometimes when I open the browser. I keep wondering if it’s just me

    • quick_snail@feddit.nl
      link
      fedilink
      arrow-up
      1
      ·
      3 days ago

      If it’s in the official fdroid, it’s met some very strict inclusion criteria.

      Read the anti feature warnings it’s all very clear.