spot_img

StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

- Advertisement -

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

- Advertisement -

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

Meta Declares Quarterly Cash Dividend Of $0.525 Per Share

Facebook parent company, Meta Platforms Inc. (NASDAQ:META) said its board of directors has declared a quarterly cash dividend of $0.525 per share on its...

Lok Sabha: Government releases ₹68K crore under MGNREGS; wage payments routed via DBT

New Delhi, India: Union Agriculture Minister Shivraj Singh Chouhan said the government has released 68,393.67 crore rupees to states and Union Territories under the Mahatma Gandhi National Rural Employment Guarantee Scheme (MGNREGS) in the current financial year 2025-26. In a written reply in the Lok...

The Evolving Classroom: Venkateshwar International School’s Pooja Sharma on Changing Role of Schools in Delhi’s CBSE Ecosystem

Speaking with TechGraph, Pooja Sharma, Vice Principal of Venkateshwar International School (VIS), discussed how...

Digital Generics: How AI is Redefining the Future of Affordable Medicine

It was with pride that global headlines described India as the world's pharmacy, supplying...

Why NoSQL Databases Are the Future for Tech Startups

In today’s digital-first economy, tech startups continue to dominate the startup landscape. A startup...

Delhi IGI Airport Revamped Terminal 2 with Advanced Baggage screening systems

Delhi’s Indira Gandhi International Airport (IGI) has reopened its reconstructed Terminal 2, inaugurated by...

The Rise of the AI Agent Economy: How Voice AI Agents Are Becoming the New Frontline Workforce For Call Centers

The work inside a call center has always depended on two things: speed and...

The Road to Equality in Tech: Women In Cloud’s Chaitra Vedullapalli on Reshaping Opportunity for Women Entrepreneurs Globally

In an interview with TechGraph, Chaitra Vedullapalli, Co-Founder of Women In Cloud, discussed how...

Understanding What Makes Sunscreen Truly Effective

Many people pick a sunscreen merely based on its SPF, thus they think that a higher number means better protection. However, SPF is only...

How AI is Improving Risk Management Among Crypto Traders

Over the past few years, the role of Artificial Intelligence in almost every sector...

The AI Advantage: How Intelligent Learning Solutions Are Rewriting Workforce Productivity in 2025 and Beyond

In 2025, artificial intelligence is no longer a futuristic concept — it’s the invisible...

Bajaj Financial Securities Acquires Stake in Lemnisk from Early Investors

Bajaj Financial Securities has acquired stakes in Bengaluru-based customer data platform Lemnisk through a...

The Rise of Cyber Cartels: How the Dark Web Fuels Digital Extortion?

In 2025, cybercrime has evolved beyond individual hackers or little ransomware criminal gangs into...

AI Research Startup Redrob Draws $10 Mn In Series A Funding Led By Korea Investment Partners

AI research startup Redrob has secured $10 million in its Series A round led by Korea Investment Partners with KB Investment, Kiwoom Investment, Korea...

The Future Employability Equation: PrepInsta’s Manish Agarwal on How AI Is Reshaping Student Readiness for Hiring in India

Speaking with TechGraph, Manish Agarwal, Co-Founder of PrepInsta, discussed how the increasing adoption of AI-led assessments and automated hiring platforms is shifting campus recruitment away from reliance on pedigree and location toward a more merit-driven model that values consistency, analytical reasoning, and practical application...

Norovex Review: Inside the Trading Platform Gaining Momentum

The online trading industry has entered one of its most dynamic periods in years....

Why Zero Code Exposure Is the Future of Trust in AI

AI coding assistants have quickly become indispensable for developers, promising faster deployment, cleaner code,...

Trump Says He Will Sue BBC Over Edited Broadcast of Jan 6 Speech

US President Donald Trump has said he plans to take legal action against the...

Starbucks Baristas Rally in New York as Strike Over Pay and Staffing Extends Nationwide

Starbucks baristas rallied in New York City as part of an open-ended strike that...

Demystifying Private Equity Market: WWIPL MD Krishna Patwari on Expanding Retail Access to India’s Unlisted Ecosystem

Speaking with TechGraph, Krishna Patwari, Founder and Managing Director of Wealth Wisdom India Pvt....

The Aesthetic of Longevity: Aesthetica’s Tanisha Bansal Gokharu on Redefining Luxury Home Interiors

Speaking with TechGraph, Tanisha Bansal Gokharu, Founder and Principal Designer at Aesthetica, discussed how...

Empowering Creators: Studiobackdrops’ Archisman Misra on Making Professional Production Accessible Across India

Speaking with TechGraph, Archisman Misra, CEO and Founder of Studiobackdrops, discussed how India’s fast-growing...

Trade Gaia Emerges as a Key Player in Global Altcoin Trading

While Bitcoin continues to dominate headlines, the real growth in 2025 is coming from...

The Conversation Shift: Doceree CRO Thomas Shea on Making Healthcare Marketing More Relevant for Physicians

Speaking with TechGraph, Thomas Shea, Chief Revenue Officer (CRO) at Doceree, discussed how artificial...

Bajaj Financial Securities Acquires Stake in Lemnisk from Early Investors

Bajaj Financial Securities has acquired stakes in Bengaluru-based customer data platform Lemnisk through a...

Digit Life Insurance posts 31% rise in H1 FY26 revenue to ₹858 crore

India-based, Go Digit Life Insurance said its revenue for the first half of FY...

Debt Recovery Reinvented: Collectedge’s Ranjan Agarwal on Reshaping India’s Collections Ecosystem for Lenders

Speaking with TechGraph, Ranjan Agarwal, CEO and Co-Founder of Collectedge, discussed how India’s debt...

AI as a Growth Multiplier: How Smart Companies Accelerate Without Breaking

In today’s business environment, smart growth is just as important as any other form...

Beyond Price Points: Unix India’s Imran Kagalwala on Redefining Consumer Expectations in the Mobile Accessories Market

Speaking with TechGraph, Imran Kagalwala, Co-founder of Unix India, discussed how a crowded accessories...

The Rise of Cyber Cartels: How the Dark Web Fuels Digital Extortion?

In 2025, cybercrime has evolved beyond individual hackers or little ransomware criminal gangs into...

Trade Gaia Emerges as a Key Player in Global Altcoin Trading

While Bitcoin continues to dominate headlines, the real growth in 2025 is coming from...

How Fleet Maintenance Scheduling Supports Business Vehicle Performance

Managing a fleet of vehicles can be challenging for any business. From delivery vans...

The Conversation Shift: Doceree CRO Thomas Shea on Making Healthcare Marketing More Relevant for Physicians

Speaking with TechGraph, Thomas Shea, Chief Revenue Officer (CRO) at Doceree, discussed how artificial...