India's Budget 2025-26 cOVEAGE
Presented by:
spot_img

StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

- Advertisement -

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

BUDGET 2025: Sustainability Sector Hopes for Strong Budget Support to Drive Clean Energy and Circular Economy

As the Union Budget 2025 draws near, expectations are building in the sustainable and waste management sector for policies that encourage the growth of...

Solar, Renewable Sector Expects Tax Breaks, Subsidies for BESS & Solar Financing Reform From Budget 2025

As Union Budget 2025 approaches, renewable energy leaders are urging Finance Minister Nirmala Sitharaman to introduce tax incentives and subsidies for Battery Energy Storage Systems (BESS) to foster clean energy innovation. Industry experts also requested the government to improve access to affordable financing through...

Gaming Industry Eyes Budget 2025 for Relief on GST and Boosted AVGC Support

With the Union Budget just days away, the gaming sector is growing hopeful that...

Budget 2025: Tax Reforms, Infrastructure Financing, and NBFC Support Top Budget Wishlist

As Budget 2025 approaches, experts from the NBFC, finance, and business sectors are voicing...

Krikya Bangladesh Casino App Review

The Krikya app delivers a seamless and engaging mobile gambling experience for users of...

IIFL Finance Thane Branch Raided by Income Tax Authorities

The Income Tax Department carried out a search operation on Tuesday morning at IIFL...

Budget 2025: Crypto Sector Looks For TDS Cuts, Loss Clarity and Investor-Friendly Tax Rules

As the Union Budget 2025 approaches, the Indian cryptocurrency industry is urging the government...

Budget 2025: Fintech Sector Hopes for Regulatory Support in Digital Lending and AI Investments

As Union Finance Minister Nirmala Sitharaman prepares to present the Budget 2025 on February...

Adoption of Low Code Platforms by MSMEs for Operational Efficiency of Their Supply Chains

Micro, small, and medium enterprises are the backbone of the world and account for over 90% of businesses globally. These enterprises are on the...

Union Budget 2025: Tech Industry Looks to Govt for AI-Focused Reforms and Tax Relief

The IT and tech industry has outlined its wishlist for the upcoming Union Budget...

Union Budget 2025 Expectations: Housing, Real Estate Sector Call for Middle-Class Relief and Affordable Housing Revival

With just days to go before the Union Budget 2025, leaders from the real...

GPS Renewables Appoints Central Bank of India ex-MD Homai Ardeshir Daruwalla As Independent Director

GPS Renewables, an India-based biogas engineering company on Monday announced the appointment of...

REVIEW: PokieSurf Casino Mobile Gaming Experience

If you’re chasing the thrill of online casino no deposit bonus free spins Australia,...

EV Sector Call for 5% GST, ITC Reforms, and Enhanced PLI in Budget 2025

As the date for the Union Budget 2025 draws near, the electric vehicle (EV) industry has outlined specific expectations that aim to accelerate growth...

Budget 2025 Expectations: Education Sector Call for Investment in Education Infrastructure and Support for Skill Training

With the Union Budget 2025 on the horizon, the education and skill development sector has emphasized the need for targeted funding to enhance both accessibility and quality. Leaders are calling for subsidies and tax breaks for education expenses and dedicated support to improve digital...

Budget 2025 Expectations: Health Sector Seeks More Funds for Cancer Care, Mental Health, and Telemedicine

Ahead of the Union Budget 2025, stakeholders from the health, healthcare, pharmacy, and medical...

The Evolution of Gaming: Key Trends Shaping the Industry in 2025

The gaming industry in 2025 is a mosaic of innovation, creativity, and cultural impact....

Budget 2025 Expectations: FHRAI Expects Reforms to Boost Hospitality and Tourism Sector

The Federation of Hotel & Restaurant Associations of India (FHRAI), has outlined its expectations...

Union Budget 2025 Expectations: India Inc. Expects Tax Reforms, Startup Incentives, and Support for MSMEs

As the Union Budget 2025 approaches, Business leaders from across industries are urging Finance...

Top Cybersecurity Practices for Small Businesses: Why a VPN is a Must-Have

In today's hyperconnected world, small businesses face a growing number of cybersecurity threats that...

Budget 2025 Expectations: Taabi Mobility CEO Pali Tripathi says, Logistics Sector Looks for Tech and Sustainability Focus in India’s Budget 2025

With Union Budget 2025 approaching, the logistics industry highlights the need for government action...

ECO Hotels & Resorts Ltd Opens 60 Room Property In Bengaluru

ECO Hotels & Resorts Limited, a stock exchange-listed mid-segment hotel chain has today said...

Vehant Technologies Secures $9 Mn from True North via NCD

Vehant Technologies, a provider of AI-driven security and surveillance solutions, has raised $9 million...

Delhi High Court Shields Upstox Trademark Rights, Targets Telegram Violators

Delhi High Court has granted an interim injunction in favor of RKSV Securities India...

GPS Renewables Appoints Central Bank of India ex-MD Homai Ardeshir Daruwalla As Independent Director

GPS Renewables, an India-based biogas engineering company on Monday announced the appointment of...

Manual Trading vs AI Trading – What Fund Managers Should Know

Trading floors that once thrived on chaos and human interaction have given way to...

Budget 2025 Expectations: Delayed Payments and Skill Gaps Dominate MSME Sector’s Wishlist

As India’s Finance Minister Nirmala Sitharaman prepares to present the Union Budget 2025, expectations...

Finbok Reviews | How Finbok Attracts and Retains New Traders Around the Globe in 2025

In the competitive world of online trading, choosing the right platform is essential for...

Budget 2025 Expectations: GST Overhaul Tops Budget 2025 Wishlist for Business and Global Competitiveness

As India prepares for the Union Budget 2025, business leaders are sharing their hopes...

REVIEW: PokieSurf Casino Mobile Gaming Experience

If you’re chasing the thrill of online casino no deposit bonus free spins Australia,...

Vehant Technologies Secures $9 Mn from True North via NCD

Vehant Technologies, a provider of AI-driven security and surveillance solutions, has raised $9 million...

Botanic Healthcare draws $30 Mn in fresh round funding

Telangana-based nutraceutical company, Botanic Healthcare today announced that it has raised ₹250 crore (approximately...

Delhi High Court Shields Upstox Trademark Rights, Targets Telegram Violators

Delhi High Court has granted an interim injunction in favor of RKSV Securities India...