Security News > 2023 > January > StrongPity Hackers Distribute Trojanized Telegram App to Target Android Users

StrongPity Hackers Distribute Trojanized Telegram App to Target Android Users
2023-01-10 16:40

The advanced persistent threat group known as StrongPity has targeted Android users with a trojanized version of the Telegram app through a fake website that impersonates a video chat service called Shagle.

"A copycat website, mimicking the Shagle service, is used to distribute StrongPity's mobile backdoor app," ESET malware researcher Lukáš Štefanko said in a technical report.

"The app is a modified version of the open source Telegram app, repackaged with StrongPity backdoor code."

The backdoor functionality is concealed within a legitimate version of Telegram's Android app that was available for download around February 25, 2022.

Another notable aspect of the attack is that the tampered version of Telegram uses the same package name as the genuine Telegram app, meaning the backdoored variant cannot be installed on a device that already has Telegram installed.

"This might mean one of two things - either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication," Štefanko said.


News URL

https://thehackernews.com/2023/01/strongpity-hackers-distribute.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Telegram 6 6 26 3 0 35
Android 4 0 17 2 0 19