New Android Spyware Found Posing as Telegram and Threema Apps

A hacking group known for its attacks in the Middle East, at least since 2017, has recently been found impersonating legitimate messaging apps such as Telegram and Threema to infect Android devices with a new, previously undocumented malware.

- Advertisement -

“Compared to the versions documented in 2017, Android/SpyC23.A has extended spying functionality, including reading notifications from messaging apps, call recording and screen recording, and new stealth features, such as dismissing notifications from built-in Android security apps,” cybersecurity firm ESET said in a Wednesday analysis.

First detailed by Qihoo 360 in 2017 under the moniker Two-tailed Scorpion (aka APT-C-23 or Desert Scorpion), the mobile malware has been deemed “surveillance ware” for its abilities to spy on the devices of targeted individuals, exfiltrating call logs, contacts, location, messages, photos, and other sensitive documents in the process.

In 2018, Symantec discovered a newer variant of the campaign that employed a malicious media player as a lure to grab information from the device and trick victims into installing additional malware.

New Android Spyware Found Posing as Telegram and Threema Apps
New Android Spyware Found Posing as Telegram and Threema Apps

Then earlier this year, Check Point Research detailed new signs of APT-C-23 activity when Hamas operators posed as young teenage girls on Facebook, Instagram, and Telegram to lure Israeli soldiers into installing malware-infected apps on their phones.

- Advertisement -

The latest version of the spyware detailed by ESET expands on these features, including the ability to collect information from social media and messaging apps via screen recording and screenshots, and even capture incoming and outgoing calls in WhatsApp and read the text of notifications from social media apps, including WhatsApp, Viber, Facebook, Skype, and Messenger.

The infection begins when a victim visits a fake Android app store called “DigitalApps,” and downloads apps such as Telegram, Threema, and message, suggesting that the group’s motivation behind impersonating messaging apps is to “justify the various permissions requested by the malware.”

In addition to requesting invasive permissions to read notifications, turn off Google Play Protect, and record a user’s screen under the guise of security and privacy features, the malware communicates with its command-and-control (C2) server to register the newly infected victim and transmit the device information.

The C2 servers, which typically masquerade as websites under maintenance, are also responsible for relaying the commands to the compromised phone, which can be used to record audio, restart Wi-Fi, uninstall any app installed on the device, among others.
What’s more, it also comes equipped with a new feature that allows it to stealthily make a call while creating a black screen overlay to mask the call activity.

“Our research shows that the APT-C-23 group is still active, enhancing its mobile toolset and running new operations. Android/SpyC32.A – the group’s newest spyware version — features several improvements making it more dangerous to victims,” ESET said.

- Advertisement -

Apps downloaded from fraudulent third-party app stores has been a conduit for Android malware in recent years. It’s always essential to stick to official sources to limit risk, and scrutinize permissions requested by apps before installing them on the device.

Also Read:


Xiaomi India Black Friday sale

Xiaomi has announced that it will be holding a Black Friday sale in India, starting from November 26, which will go on till November...

YouTube 8K Streaming Support Reportedly Rolling Out to Select Android TV Users

YouTube is reportedly rolling out 8K streaming support for select Android TV users as part of the company’s plans to possibly bring the feature to all users everywhere. According...

Moto G 5G VS Oneplus Nord

Moto G series is one of the most recognized series in the Indian smartphone market. They had been doing great with their G series...

Moto G 5G launched in India

Motorola has launched its mid-range smartphone Moto G 5G in India . This smartphone has been launched in gray and silver colors and this Android One smartphone will be available on Flipkart from 7...

Download (Google Camera) Gcam 7.3 APK mod for all Android devices

Gcam (Google Camera) is a camera phone application developed by Google for Android. It was initially supported on all devices running Android 4.4 KitKat and higher but is now only officially...

Leave A Reply

Please enter your comment!
Please enter your name here