Skip to finding
important · Mobile

Google Play-distributed Joker variants can turn infected Android phones into proxy exit nodes.

Affects

Android.Joker, a family of trojanized Android applications distributed through Google Play and other app channels.

The victim must install and run a trojanized Android application.

Detail and 1 source

The newly reported module relays third-party traffic through the handset, giving its operator the victim’s mobile network identity as an exit point.

The capability change is the addition of proxy egress to variants that were distributed through Google Play.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026