spot_img

StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

- Advertisement -

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

- Advertisement -

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

Techugo Appoints Akshay Gupta as Vice President of IT for Global Markets

In a move to expand into new markets, Techugo, a global mobile application and digital transformation company, has appointed Akshay Gupta as Vice President...

Foreign Secretary Cooper Denies UK’s Role in U.S. Operation Against Venezuela’s Maduro

The British Foreign Secretary, Yvette Cooper, said the UK was not involved in the recent U.S. operation targeting Venezuela, including the reported capture of President Nicolás Maduro and his wife, Silvia Flores. Addressing Parliament, Cooper said, “The United Kingdom played no role in the U.S....

6 Realities Every Independent Professional Eventually Faces

Choosing to work independently is a dream for many. The freedom to set your...

US President Trump Says PM Modi “Knew I Was Not Happy,” Links India’s Russian Oil Import Cuts to Tariff Threats

US President Donald Trump praised Indian Prime Minister Narendra Modi for what he described...

NCB Advises Indian Travellers to Seek Clearance for Carrying Medicines to Saudi Arabia

The Narcotics Control Bureau has advised Indian travellers to obtain the required approvals before...

Why Edge Data Centres are India’s Next Growth Frontier

India's digital economy has entered a stage where promoting growth is no longer sufficient,...

India, Pakistan Share Details of Prisoners and Fishermen Held in Custody

India and Pakistan today exchanged the lists of civilian prisoners and fishermen in each...

India, Pakistan Exchange List of Nuclear Facilities Under Bilateral Agreement

India and Pakistan today exchanged the list of Nuclear Installations and facilities covered under...

India Extends Textile PLI Application Deadline to March 31

India has extended the deadline for submission of fresh applications under the Production Linked Incentive (PLI) Scheme for Textiles until March 31 this year. The...

Scaling Conversations: Superbot AI’s Sarvagya Mishra on Building Regional Voice AI for India’s Linguistic Markets

Speaking with TechGraph, Sarvagya Mishra, Founder and Director of Superbot, discussed how India’s shift...

The Hidden Business Layer Behind IoT Connectivity

When people talk about the Internet of Things, the focus is usually on devices....

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...

Rewiring Academic Research: MBU’s Dr. T.V.V. Satyanarayana on How IECom Is Shaping India’s Intelligent Electronics Agenda

Speaking with TechGraph, Dr. T.V.V. Satyanarayana, Professor at Mohan Babu University (MBU), discussed how...

Building a Future-Ready Portfolio in a Digitally Driven Economy

The rapidly changing investment landscape in India has the nation's fast-growing digital economy at its center. Technology is affecting how companies operate, how consumers...

Why BFSI Needs Generative AI, Not Rule Engines

The Banking, Financial Services, and Insurance (BFSI) sector has been using rule engines for decision automation, workflow management, and regulatory compliance for decades. These systems, based on predefined logic and static if-then conditions, worked in a fairly predictable financial environment. However, the present-day BFSI scenario...

How Unified Intelligence Is Transforming the Future of Device Security

Device security has always been a balancing act; protecting sensitive data without slowing the...

Enterprise Blind Spots: 3 Cubed’s Shammik Gupta on Building a Digital Twin for Real Operational Clarity

Speaking with TechGraph, Shammik Gupta, Founder of 3 Cubed, discussed how enterprises invested in...

How Self-Service Analytics Is Reshaping Everyday Business Decisions

For years, analytics ran on a predictable cycle. Business teams raised requests and waited...

How can mid-career professionals transition into AI-assisted roles without going back to college?

Artificial intelligence is reshaping industries worldwide, from healthcare to finance, marketing, logistics, and education....

Adda247’s Bimaljeet Singh Bhasin on Career247 and the Push for Job-Ready Education

In an interview with TechGraph, Bimaljeet Singh Bhasin, CEO of Skilling and Higher Education...

The Future of Preventive Healthcare in India and the Role of Digital Platforms

India is set to decide on the ongoing healthcare evolution, where the main point...

Rethinking Medical Training: MedLern Co-founder Deepak Sharma on Digital Resuscitation Learning and Patient Safety

Speaking with TechGraph, Deepak Sharma, Co-founder and CEO of MedLern, discussed how traditional instructor-led...

Home Improvements That Benefit You Today and Boost Value Tomorrow

When it comes to home improvements, the best upgrades are those that provide immediate...

Vimal Singh on ReadyAssist’s Role in Modernising Roadside Assistance in India

Speaking with TechGraph, Vimal Singh, Founder of ReadyAssist, discussed how traditional roadside assistance models...

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...

Why Solar Panels Are a Worthwhile Investment

With the increasing urgency to transition to sustainable energy sources, investing in solar panels...

Tech Driven Urban Growth: How Digital Innovation is Shaping Sustainable Real Estate in India’s Emerging Cities

India stands at an important moment in its urban journey. The country’s largest cities...

Ensuring Your Building is Technologically Modern and Eco-Friendly

In the contemporary world, where the balance between innovation and sustainability is paramount, modernizing...

Serhiy Tokarev on the Four Hidden Advantages of the CEE Startup Ecosystem

Central and Eastern Europe (CEE) has changed a lot in the last ten years....

Rewiring Academic Research: MBU’s Dr. T.V.V. Satyanarayana on How IECom Is Shaping India’s Intelligent Electronics Agenda

Speaking with TechGraph, Dr. T.V.V. Satyanarayana, Professor at Mohan Babu University (MBU), discussed how...

Home Improvements That Benefit You Today and Boost Value Tomorrow

When it comes to home improvements, the best upgrades are those that provide immediate...

India’s AIF Shift: Steptrade Capital’s Kresha Gupta on the Evolution of Alternative Investments in India

Speaking with TechGraph, Kresha Gupta, Director and Fund Manager at Steptrade Capital, discussed how...

Vimal Singh on ReadyAssist’s Role in Modernising Roadside Assistance in India

Speaking with TechGraph, Vimal Singh, Founder of ReadyAssist, discussed how traditional roadside assistance models...