Security News > 2023 > September > 'Evil Telegram' Android apps on Google Play infected 60K with spyware

At the time the researchers published their report, several malicious apps were still available for download through Google Play.
The Telegram apps presented in Kaspersky's report are promoted as "Faster" alternatives to the regular app.
Google has since taken these Android apps off Google Play and shared the following statement with BleepingComputer.
Late last month, ESET warned about two trojanized messaging apps, Signal Plus Messenger and FlyGram, promoted as more feature-rich versions of the popular open-source Signal and Telegram apps.
Now removed from Google Play and the Samsung Galaxy Store, those apps contained the BadBazaar malware that allowed their operators, the Chinese APT 'GREF,' to spy on their targets.
Trojanized Signal and Telegram apps on Google Play delivered spyware.
News URL
Related news
- New North Korean Android spyware slips onto Google Play (source)
- Malicious Android 'Vapor' apps on Google Play installed 60 million times (source)
- Google's March 2025 Android Security Update Fixes Two Actively Exploited Vulnerabilities (source)
- How Google tracks Android device users before they've even opened an app (source)
- Google fixes Android zero-day exploited by Serbian authorities (source)
- Google expands Android AI scam detection to more Pixel devices (source)
- Google Rolls Out AI Scam Detection for Android to Combat Conversational Fraud (source)
- Google Gemini's Astra (screen sharing) rolls out on Android for some users (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities (source)