StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

- Advertisement -

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

00:01:09

VIDEO: US President Donald Trump Calls NBC A ‘Work Network’ On Television

During a press meeting at the Oval Office on Wednesday, US President Donald Trump criticized a reporter by calling NBC the 'worst network' on...

The Role of Edge Computing in AI-Powered Cloud Solutions

With businesses including artificial intelligence (AI) in their operations, cloud computing has grown in significance for its administration and processing. Conventional cloud-based artificial intelligence systems, however, struggled with data security, bandwidth use, and latency. Consequently, this resulted in the development of edge computing. By...

From Startup to Success: Essential Steps for Landscaping Entrepreneurs

Starting a landscaping business is so exciting, blending creativity with the reward of transforming...

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and...
00:08:45

Trade War: Canadian PM Justin Trudeau Announces 25% Tariffs On US Imports

Ottawa: Canadian Prime Minister Justin Trudeau on Wednesday announced a 25% tariff on U.S....

RP-Sanjiv Goenka’s Firstsource Opens ANZ HQ and AI Lab in Melbourne

Firstsource Solutions Limited (NSE: FSL, BSE:532809), an RP-Sanjiv Goenka Group company, today announced the...

Meta COO Javier Olivan Offloads Shares Worth $409,768

Meta Platforms (NASDAQ: META) Chief Operating Officer Javier Olivan is set to sell 608...

Personal branding: designing logos for influencers and creators

In today’s digital landscape, personal branding has become more than just a buzzword; it’s...
00:03:00

Trump Defends Elon Musk Plan for Federal Job Cuts; Govt Spending ‘Bloated’

Following a meeting with Elon Musk and senior cabinet members, U.S. President Donald Trump said Friday that the federal government’s workforce is “out of...

Demand for plumbers in Oman: which specialists are most in demand?

The demand for skilled plumbers in Oman is steadily increasing due to the country's...

Meta Executive Chris Cox to Sell $13.5 Million in Shares

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox has filed to sell 20,000...

Union Budget 2025-26 Reactions: EV Makers Welcome Tax Relief and Infrastructure Investments

India’s electric vehicle industry has welcomed the Union Budget 2025-26, citing exemptions on capital...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding (MoU) with the Startup Policy Forum (SPF) to drive data-driven...

Sachin Tendulkar Backed RRP Electronics Partners with Deca Technologies To Enhance Semiconductor Packaging

Cricketing legend Sachin Tendulkar-backed semiconductor manufacturer RRP Electronics has signed a strategic partnership with US-based Deca Technologies, Inc. to enhance its wafer-level packaging capabilities. "As a part of the partnership, RRP Electronics—renowned for its expertise in assembling and testing semiconductor components—will integrate Deca’s cutting-edge Wafer-Level...

Ways Technology Can Help Your Business Performance

Businesses of all sizes and across every industry are integrating technology to improve their...

Microsoft Makes Equity Investment in Veeam

American tech giant Microsoft has made an equity investment in Veeam Software to develop...

Dogsee Chew draws $8 Mn in series B round from Ektha & Others

Natural pet treat brand Dogsee Chew on Thursday said, it has raised $8 million...

Simplifying International Transfers: A New Era for Indian Immigrants in Canada

Every year, thousands of Indian professionals and families pack their lives into suitcases and...

Lado Okhotnikov: A Successful Entrepreneur Who Has Inspired Millions

Lado Okhotnikov is a successful entrepreneur, expert, publicist, and investor from Kazakhstan, widely recognized...

PDF and eSignature Solution Provider Foxit Promotes Andrew Travis to Chief Revenue Officer

Foxit, Fremont, CA-based leading PDF and eSignature solution provider, on Tuesday announced that it...

Life Insurance Death Benefit Payouts: What Your Family Needs to Know

It is important to know more about life insurance policies and their operational modalities....

Wired vs. Wireless Headsets: A Comparative Guide for Evolving Audio Needs

Across a wide range of demographics, including gamers, fitness enthusiasts, business executives, and remote...

Union Budget 2025: Real Estate Experts See SWAMIH 2.0, ₹15,000 Cr State Support to Ease Housing Bottlenecks

The real estate sector views the Union Budget 2025-26 as a step toward addressing...

Union Budget 2025-26 Reactions: EV Makers Welcome Tax Relief and Infrastructure Investments

India’s electric vehicle industry has welcomed the Union Budget 2025-26, citing exemptions on capital...

Adani Wilmar Gets Shareholders’ Approval to Rebrand as AWL Agri Business Limited

Stock exchange-listed Adani Wilmar Limited announced on Tuesday that it has received approval from...

Pakistan Begins Rice Exports to Bangladesh Under New Government Deal

Bangladesh and Pakistan have resumed direct trade for the first time since 1971. The...

Leveraging AI and Modern HR Solutions to Transform Recruitment Strategies for Skilled Workers

In today’s competitive job market, recruitment strategies are rapidly evolving, driven by advancements in...

BC Originals: Exclusive Casino Games on BC.Game

BC Originals are special, exclusive casino games that are just for BC.Game players. All...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...

Wired vs. Wireless Headsets: A Comparative Guide for Evolving Audio Needs

Across a wide range of demographics, including gamers, fitness enthusiasts, business executives, and remote...

The Rise of Conversational AI: What It Means for Tech and SaaS Businesses

Back in the time, when AI was not as prominent, businesses used to struggle...

Union Budget 2025: Real Estate Experts See SWAMIH 2.0, ₹15,000 Cr State Support to Ease Housing Bottlenecks

The real estate sector views the Union Budget 2025-26 as a step toward addressing...