spot_img

StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

SustVest Secures $1.7 Mn in pre-Series A round

Haryana-based sustainable investment platform SustVest has raised $1.7 million in a mix of equity and debt as part of its pre-Series A funding round. The...

Web3 in Supply Chain: Qila’s CEO Siddharth Ugrankar On Simplifying Blockchain Adoption for Business

Speaking to TechGraph, Siddharth Ugrankar, CEO of Qila.io highlighted the potential of the company's permissioned blockchain workflows and customizable SaaS platform, and how these solutions enable businesses to tokenize high-end retail, track supply chains, and ensure compliance with ESG standards and ethical sourcing. Read the...

GAMES: Lucky Green Casino Experience

If you’re in search of an exhilarating gaming platform that balances high-stakes thrills with...

Securing the Future of AI: Nuvepro CEO Giridhar LV on Generative AI & a Human-First Approach

During a conversation with TechGraph, Nuvepro Co-founder and CEO Giridhar LV discussed the company's...

Driving ROI Through AI: CEO Dipal Dutta on RedoQ’s Hybrid Approach to Automation

Speaking to TechGraph, Dipal Dutta, CEO and Founder of RedoQ, explained how the company...

What is RTP and How Does It Affect Slots Winnings?

If you’ve ever played a slot game, you’ve likely come across the term "RTP."...

Godrej Capital’s Gen AI Plan: CTO Jyothirlatha B on SAKSHAM AI and the Future of Financial Services

Speaking to TechGraph, Godrej Capital CTO Jyothirlatha B shared how the company is harnessing...

Preparing for a Data-Driven Future: How the GRE Assesses Academic and Analytical Readiness

As sectors such as artificial intelligence (AI) and machine learning continue to grow and...

Reshaping India’s Farming Future: Balwaan Krishi’s Rohit Bajaj On Driving Agricultural Change

Speaking to TechGraph, Rohit Bajaj, Co-Founder of Balwaan Krishi, discusses the company’s commitment to transforming India’s diverse farming landscape through affordable mechanization solutions and...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

build3 Launches Second Cohort of Impact Startup Academy

build3, an ecosystem championing startups that merge profit with purpose has today announced the...

How Generative AI is Shaping Voicebot Capabilities

The advent of Generative AI is here to revolutionize the technological landscape and reimagine...
00:08:12

Congress-Led Opposition Calls for Vice President Dhankhar Removal

India Congress lead opposition coalition also known as the INDIA bloc, has formally submitted a notice seeking the removal of Vice President Jagdeep Dhankhar,...

‘Historic day for the Middle East’: PM Netanyahu On Syria’s Assad Regime Collapse

Israeli Prime Minister Benjamin Netanyahu, in a video statement released on Sunday, described the collapse of Syrian President Bashar al-Assad’s regime as a pivotal moment for the region, calling it a “historic day for the Middle East.” While expressing optimism over emerging opportunities, he...

Decentralizing Cardiac Care: Sunfox Technologies’ Rajat Jain on the Spandan ECG Impact

During an interview with the TechGraph editorial team, Sunfox Technologies' Founder and CEO, Rajat...

Boson Whitewater, Citadines OMR Chennai to Launch First-of-its-Kind Wastewater Recycling System

Boson Whitewater, a water utility company that converts STP-treated water into high-quality potable water,...

Titan Intech Ltd To Secure Rs 200 Cr via NCDs

Titan Intech Limited, a BSE-listed company specializing in Embedded Manufacturing Services (EMS) for OEM/ODM...

Ensuring Fair Play: AIGF CEO Roland Landers on Promoting Skill-Based Gaming in India

During an interview with TechGraph, Roland Landers, CEO of the All India Gaming Federation...

The Evolution of Gaming: From Traditional to Immersive Online Experiences

Gaming has undergone a remarkable transformation over the decades, evolving from basic, tactile forms...

The Role of Health Plans with Preventive Care in Reducing Financial Risk

In an era where healthcare costs are spiraling and chronic conditions are on the...

The Impact of Real-Time Market Data Solutions on Informed Trading Decisions

The world of finance isn’t stagnant; it is dynamic and ever-evolving. Every second, a...

AI and Workplace Equality for Women in the Digital Era

As society heads toward an age dominated by technology, a key question remains: will...

Order for Health (O4H) Snaps INR 1 Cr In Series Seed Round Funding

Order for Health (O4H), a Bengaluru-based healthy food brand, has secured INR 1 crore...

build3 Launches Second Cohort of Impact Startup Academy

build3, an ecosystem championing startups that merge profit with purpose has today announced the...

Jungle Camps India Limited Sets IPO Price Band at ₹68-₹72 per Share

Jungle Camps India Limited (JCIL), an India-based ecological hospitality service provider on Thursday announced...

Atmosphere The Store Makers draws INR 5 Cr in seed round

Mumbai based Atmosphere – The Store Makers on Thursday raised INR 5 crore in...

Top Trends in Web3 Platforms for Forward-Thinking Entrepreneurs

The digital landscape is evolving rapidly, and Web3 platforms are leading this transformation. For...
00:00:20

Benjamin Netanyahu: Thank You President Donald Trump for Calling Hamas to Release Hostages

Israeli Prime Minister Benjamin Netanyahu on Tuesday expressed his gratitude to U.S. President-Elect Donald...

How Generative AI is Shaping Voicebot Capabilities

The advent of Generative AI is here to revolutionize the technological landscape and reimagine...

AI and Workplace Equality for Women in the Digital Era

As society heads toward an age dominated by technology, a key question remains: will...

OPPO, Microsoft Teams up To Bring Advanced AI Productivity To ColorOS 15

OPPO has strengthened its partnership with Microsoft to deliver advanced AI productivity features to...

Order for Health (O4H) Snaps INR 1 Cr In Series Seed Round Funding

Order for Health (O4H), a Bengaluru-based healthy food brand, has secured INR 1 crore...