<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Android · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/android/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Sat, 01 Aug 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/android/index.xml" rel="self" type="application/rss+xml"/><item><title>Three locks, and the key left in</title><link>https://blog.efespain.com/en/chapter-13/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-13/</guid><description>In chapter 10 I caught the miner, but not the thing that hands it out: that part I told on loan, using someone else's analysis. The honeypot holds a grudge, and brought me the whole thing — armoured three times over, with a blob that resisted everything I know how to do. Until I stopped trying to read it.</description></item><item><title>A miner that got a bit lost</title><link>https://blog.efespain.com/en/chapter-10/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-10/</guid><description>Another APK came in through the debug cable, but this one weighs fifteen times less than the last and doesn't carry a single line of native code. I opened it expecting something mediocre. What I found was a 2018 fossil still infecting phones to mine for a company that shut down seven years ago — and which today, without knowing it, warns its own victims.</description></item><item><title>Sysorbit laid bare: three layers to hide one address</title><link>https://blog.efespain.com/en/chapter-8/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-8/</guid><description>We peel the APK apart layer by layer: a DEX that's nothing but a launcher, an app that nails itself into /system if there's root, and a native DDoS engine. The C2 slammed the door in my face — until I came back another way and it opened.</description></item><item><title>The one that came in through the debug cable</title><link>https://blog.efespain.com/en/chapter-7/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-7/</guid><description>The previous three went after servers. This one went after a phone: it came in through ADB, wiped out the competition, installed its app disguised as Google, and hid itself. First Android malware in the honeypot.</description></item></channel></rss>