Spyware disguised as modified versions of Telegram have been spotted in the Google Play Store which were installed over 60,000 times and are designed to harvest sensitive information from compromised Android devices.
The apps were discovered by Kaspersky, who reported them to Google. The activity has been codenamed Evil Telegram by the Russian cybersecurity company.
The apps appear to be designed for Chinese-speaking users and the Uighur ethnic minority, suggesting possible ties to the well-documented state monitoring and repression mechanisms.
According to the security analysts, the apps are the same as the original Telegram but contain additional functions in the code to steal user messages, contacts lists, and other data.
Specifically, there’s an extra package named ‘com. wsys’ that accesses the user’s contacts and also collects the victim’s username, user ID, and phone number.
When the user receives a message through the trojanized app, the spyware sends a copy straight to the operator’s command and control (C2) server at “sg[.]telegrnm[.]org”
The exfiltrated data, which is encrypted prior to transmission, contains the message contents, chat/channel title and ID, and the sender’s name and ID.
The spyware app also monitors the infected app for changes to the victim’s username and ID and changes to the contacts list, and if anything changes, collects the most up-to-date information.
While the malicious Evil Telegram apps used the package names ‘org.telegram.messenger.wab’ and ‘org.telegram.messenger.wob,’, the legitimate Telegram app has a package name of ‘org.telegram.messenger.web.’
Google has taken these Android apps off Google Play and the developers have been banned.
Users are recommended to use the genuine versions of messaging apps and avoid downloading forked apps that promise enhanced privacy, speed, or other features.

















Comments