cross-posted from: https://piefed.world/c/tech/p/1146502/telegram-apk-from-apkpure-is-a-spyware

On analyzing the APK with jadx, it contains a class DataCollector, which does not exist in the .apk file downloaded from the official Telegram website.

This class collects a lot of your data, including:

  • Your photos, videos, and files
  • Your contacts
  • Your messages
  • Your GPS Coordinates
  • Your SIM card information
  • Your Telegram profile

This data is monitored and uploaded continuously. All the data is uploaded to a server with IP Address 38.190.225.166

💬 Initial discovery by Eric Parker

🔗 APK Analysis: Part 1 | Part 2.

Source on Telegram.

  • DupaCycki@lemmy.world
    link
    fedilink
    arrow-up
    38
    ·
    3 days ago

    Who downloads Telegram’s apks from third party sources if they’re freely available on Telegram’s official website?

    It’s literally the first result when you search for “telegram apk” (DuckDuckGo). Followed by apkpure.