245
submitted 1 day ago* (last edited 1 day ago) by beep@piefed.world to c/youshouldknow@lemmy.world

cross-posted from: https://piefed.world/c/tech/p/1146502/telegram-apk-from-apkpure-is-a-spyware

On analyzing the APK with jadx, it contains a class DataCollector, which does not exist in the .apk file downloaded from the official Telegram website.

This class collects a lot of your data, including:

  • Your photos, videos, and files
  • Your contacts
  • Your messages
  • Your GPS Coordinates
  • Your SIM card information
  • Your Telegram profile

This data is monitored and uploaded continuously. All the data is uploaded to a server with IP Address 38.190.225.166

πŸ’¬ Initial discovery by Eric Parker

πŸ”— APK Analysis: Part 1 | Part 2.

Source on Telegram.

top 28 comments
sorted by: hot top new old
[-] corsicanguppy@lemmy.ca 3 points 13 hours ago

YSK: as a mass noun, 'spyware' doesn't need the indefinite article. We don't "a happy", for instance, and we heckle those who say "a software".

[-] quick_snail@feddit.nl 17 points 1 day ago

Anything outside the official F-Droid repo is sketch as fuck

[-] DupaCycki@lemmy.world 38 points 1 day ago

Who downloads Telegram's apks from third party sources if they're freely available on Telegram's official website?

It's literally the first result when you search for "telegram apk" (DuckDuckGo). Followed by apkpure.

[-] markz@suppo.fi 41 points 1 day ago

apk download sites seem pretty sketchy in general

[-] HeyThisIsntTheYMCA@lemmy.world 5 points 1 day ago

Not true! Download my free cracked apks at totally not a virus dot com

[-] SubArcticTundra@lemmy.ml 13 points 1 day ago

Yeah, it's the Windows .exe problem all over again

[-] clb92@feddit.dk 42 points 1 day ago

So APKPure is not trustworthy? Do they not have any verification of APKs?

[-] Mercer@nord.pub 6 points 1 day ago

maybe there were before, but now something has changed, I would recommend looking at alternatives to this site, for example in fmhy(.)net or in alternative net, but I would download the application from official sources, like the play market or open source programs in f-droid

[-] clb92@feddit.dk 14 points 1 day ago

I know that APKMirror supposedly verifies the APK files' hashes against official sources, so APKs you get there should be fine, unless the developer was compromised at some point, or unless APKMirror itself is lying, but it is run by the people behind Android Police, as far as I know.

[-] acockworkorange@mander.xyz 13 points 1 day ago

YSK: Telegram ~~APK from APKPure~~ is a spyware

[-] Swedneck@discuss.tchncs.de 2 points 14 hours ago

everything related to telegram gives me the ick

[-] huppakee@lemmy.world 3 points 1 day ago

Like small infintes and large infinites are both invites, yes

[-] HeyThisIsntTheYMCA@lemmy.world 1 points 1 day ago

Don't get me started on coubtable and ubcoubtanle. And ns that turn to vs.

[-] thenoirwolfess@fedinsfw.app 14 points 1 day ago

Nice. I wonder how clean Forkgram is

[-] quick_snail@feddit.nl 1 points 1 day ago

If it's in the official fdroid, it's met some very strict inclusion criteria.

Read the anti feature warnings it's all very clear.

[-] Staff@piefed.world 3 points 1 day ago* (last edited 1 day ago)

Forkgram is kinda sus in my phone. It's always opening notifications. Sometimes when I open the browser. I keep wondering if it's just me

[-] Angryhumanoid@fedinsfw.app 8 points 1 day ago

They can't do that, pure is right in the name!

[-] badgermurphy@lemmy.world 5 points 1 day ago

Its still made entirely of .apk.

[-] mfed1122@discuss.tchncs.de 7 points 1 day ago

This is why it really sucks that app developers offering their APKs directly isn't more common, forces people to turn to sites like this. I've installed apps from apkmirror just because I want to avoid Google Play. I don't really understand why there isn't some third party app store that helps lift the hosting+verification burden from developers but still doesn't rely on randos uploading apks from gplay.

What a great world it would be if every time you went to some software's website with an app, they had that "download from google play" button right next to a "download from " button so you know its their real account, and a "download apk" button, because why not put some faith in users?

[-] Swedneck@discuss.tchncs.de 3 points 14 hours ago

this is literally exactly why f-droid exists

[-] SomethingBurger@jlai.lu 16 points 1 day ago* (last edited 1 day ago)
[-] huppakee@lemmy.world 6 points 1 day ago

I did just upvote you but i'm also leaving a comment because that's how happy i am with Aurora Store doing the hard work

[-] stat_rosa@lemy.nl 3 points 1 day ago

This is the thing that worries me. I'm currently Degoogling and relying on sources like F-Droid, but these sneaky tricks seem unavoidable

[-] quick_snail@feddit.nl 1 points 1 day ago

Just stick to fdroid

[-] JohnDarlen@lemmy.today 4 points 1 day ago

That's why I'm extremely strict about permission I allow on my apps. My Telegram is official but still has no permission on contacts, camera or images/files.

this post was submitted on 24 May 2026
245 points (98.8% liked)

You Should Know

46006 readers
346 users here now

YSK - for all the things that can make your life easier!

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must begin with YSK.

All posts must begin with YSK. If you're a Mastodon user, then include YSK after @youshouldknow. This is a community to share tips and tricks that will help you improve your life.



Rule 2- Your post body text must include the reason "Why" YSK:

**In your post's text body, you must include the reason "Why" YSK: It’s helpful for readability, and informs readers about the importance of the content. **



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Posts and comments which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding non-YSK posts.

Provided it is about the community itself, you may post non-YSK posts using the [META] tag on your post title.



Rule 7- You can't harass or disturb other members.

If you harass or discriminate against any individual member, you will be removed.

If you are a member, sympathizer or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people and you were provably vocal about your hate, then you will be banned on sight.

For further explanation, clarification and feedback about this rule, you may follow this link.



Rule 8- All comments should try to stay relevant to their parent content.



Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- The majority of bots aren't allowed to participate here.

Unless included in our Whitelist for Bots, your bot will not be allowed to participate in this community. To have your bot whitelisted, please contact the moderators for a short review.



Rule 11- Posts must actually be true: Disiniformation, trolling, and being misleading will not be tolerated. Repeated or egregious attempts will earn you a ban. This also applies to filing reports: If you continually file false reports YOU WILL BE BANNED! We can see who reports what, and shenanigans will not be tolerated. We are not here to ban people who said something you don't like.

If you file a report, include what specific rule is being violated and how.



Partnered Communities:

You can view our partnered communities list by following this link. To partner with our community and be included, you are free to message the moderators or comment on a pinned post.

Community Moderation

For inquiry on becoming a moderator of this community, you may comment on the pinned post of the time, or simply shoot a message to the current moderators.

Credits

Our icon(masterpiece) was made by @clen15!

founded 2 years ago
MODERATORS