this post was submitted on 14 Jul 2025
62 points (97.0% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

62787 readers
341 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

FUCK ADOBE!

Torrenting/P2P:

Gaming:


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 2 years ago
MODERATORS
 

Virus total limit is 600mb.

all 22 comments
sorted by: hot top controversial new old
[–] stupid_asshole69@hexbear.net 4 points 2 days ago

Run the md5.

Of course that only tells you that you got what the author intended, not that what they intended is “safe”

[–] ogmios@sh.itjust.works 37 points 3 days ago (1 children)
[–] admin@lemmy.today 13 points 3 days ago (1 children)

So russian roulette it is.

[–] ogmios@sh.itjust.works 7 points 3 days ago (1 children)

Just run them on a machine you don't care about, if you're concerned.

[–] pipes@sh.itjust.works 4 points 3 days ago

This, and/or in a work profile (Shelter), or even better a separate android user

[–] char_stats@discuss.tchncs.de 22 points 3 days ago

By making sure (as much as you possibly could) the source you got it from is safe.

You'll reduce the risk.

[–] sp3ctr4l@lemmy.dbzer0.com 9 points 3 days ago* (last edited 3 days ago)

Run them in a test sandbox environment, maybe run some network analytics to see if weird outbound or inbound calls start getting made... hope they are not more clever than your sandbox environment.

For APKs specifically... official support for Hypatia from the original team ended last year, but a 'MaintainTeam Organization' seems to be attempting to pick up the slack, and keep updating with new malware signatures.

https://apt.izzysoft.de/fdroid/index/apk/org.maintainteam.hypatia

https://github.com/MaintainTeam/Hypatia

... not sure if its... actually getting regular updates though.

EDIT: derp, yeah

Also, as upstroke says, do a hash comparison from the actual proper source to verify you aren't getting a malformed or spoof version of whatever APK.

[–] upstroke4448@lemmy.dbzer0.com 8 points 3 days ago (1 children)

Verify their hash signature.

[–] blah3166@piefed.social 1 points 1 day ago

The only real answer - same as with any other software/code.

[–] SheeEttin@lemmy.zip 15 points 3 days ago* (last edited 3 days ago)

Apks can be unpacked. There are plenty of offline scanners with high or no size limits too.

There are probably also Android-specific scanners.

[–] hexagonwin@lemmy.sdf.org 15 points 3 days ago

I don't. I just consider them compromised and block network connection. Usually that works fine unless it's a ransomware or something..

[–] LodeMike@lemmy.today 5 points 3 days ago

IDK install it on a VM?

[–] Aatube@kbin.melroy.org 4 points 3 days ago (1 children)
[–] Morningstar_bitch@lemmy.dbzer0.com 2 points 2 days ago (1 children)
[–] Aatube@kbin.melroy.org 1 points 2 days ago

what

hast thou never said “i pray for…” thy whole life

[–] LodeMike@lemmy.today 3 points 3 days ago (1 children)

What the fuck kind of program is that large?

[–] admin@lemmy.today 2 points 3 days ago (2 children)
[–] LodeMike@lemmy.today 3 points 3 days ago

Oh. Split the .apks apart. That might help.

[–] LodeMike@lemmy.today 1 points 3 days ago (1 children)
[–] admin@lemmy.today 1 points 3 days ago
[–] tias@discuss.tchncs.de 1 points 3 days ago

APK and APKS are just renamed zip files