cross-posted from: https://piefed.world/c/tech/p/1146502/telegram-apk-from-apkpure-is-a-spyware
On analyzing the APK with jadx, it contains a class DataCollector, which does not exist in the .apk file downloaded from the official Telegram website.
This class collects a lot of your data, including:
- Your photos, videos, and files
- Your contacts
- Your messages
- Your GPS Coordinates
- Your SIM card information
- Your Telegram profile
This data is monitored and uploaded continuously. All the data is uploaded to a server with IP Address 38.190.225.166
💬 Initial discovery by Eric Parker


Forkgram is kinda sus in my phone. It’s always opening notifications. Sometimes when I open the browser. I keep wondering if it’s just me