StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

- Advertisement -

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

OPPO, Microsoft Teams up To Bring Advanced AI Productivity To ColorOS 15

OPPO has strengthened its partnership with Microsoft to deliver advanced AI productivity features to ColorOS 15, OPPO's next-generation smart device experience. "To deliver advanced AI...

Order for Health (O4H) Snaps INR 1 Cr In Series Seed Round Funding

Order for Health (O4H), a Bengaluru-based healthy food brand, has secured INR 1 crore in seed funding led by Inflection Point Ventures. The brand plans to utilize the funds to scale production, expand its market footprint, streamline operations, and open new stores. Founded with a mission...

build3 Launches Second Cohort of Impact Startup Academy

build3, an ecosystem championing startups that merge profit with purpose has today announced the...

Yoju Casino Online Review: A Comprehensive Guide for Enthusiasts

Welcome to our in-depth review of Yoju Casino, a vibrant online gaming platform that...

WeVOIS Lab’s Abhinav Vashistha On Shaping the Future of Waste Management with AI

During an interview with TechGraph, Abhinav Vashistha, Co-Founder of WeVOIS Lab, discusses how it...

The Hidden World of Mega888 APK: What Casual Players Are Missing Out On

Mega888 APK is well-known among online casino enthusiasts for its thrilling games and easy-to-navigate...

Indusface Launches CyberShiksha program to Educate Students on Cybersecurity

Indusface, a leading application security provider for SaaS solutions, has launched CyberShiksha, a national...

Crypto Market Crosses $3.08 Trn, Bitcoin Hits $91,616, Litecoin Drops Below $90

The cryptocurrency market surged to a total valuation of $3.08 trillion on Monday, with...

RULOANS Sees Surge in Digital Secured Loan Demand on RUCONNECT App

RULOANS Distribution Services, an Indian financial products distributor, has reported a significant uptake in its newly launched digital secured loan offerings on the RUCONNECT...

Voice-Based AI and SLMs: Gnani Ai CEO Ganesh Gopalan On India’s Voice AI Boom

During an interview with TechGraph, Ganesh Gopalan, Co-founder of Gnani.ai, discussed how voice-based AI,...

MoneraCap com Review: A Deep Dive into a Transformative Trading Experience

Decision that can shape your investment journey. A well-chosen platform not only enhances trading...

Live From Parliament: UK Deputy PM Angela Rayner takes PMQs

London News: The United Kingdom (UK) deputy prime minister Angela Rayner takes questions from...

LTC UPDATE: Gate io Lists Litecoin Under Meme Coins

US-based cryptocurrency exchange platform Gate.io has listed Litecoin (LTC) under its meme coin category. The...

Pokarna Engineered Stone Limited Commits Rs 440 Crores for New Bretonstone Line

Pokarna Engineered Stone Limited (PESL) said on Tuesday it will invest Rs. 440 crore to expand production capabilities at its Mekaguda facility in Telangana....

Coinbase launches COIN50 Index To Track Top 50 Cryptos On its Exchange

Leading crypto trading platform Coinbase on Tuesday announced the launch of the Coinbase 50 Index (COIN50), a regulated cryptocurrency benchmark designed to provide transparent and reliable exposure to the crypto market. Developed in partnership with Coinbase Asset Management and Market Vector Indexes, the new index...

Donald Trump To Shut Department of Education; Plans To Shift Responsibilities To States

President-elect Donald Trump announced on Monday that his administration intends to close the Department...

The Trump Effect: Crypto Market Hits $3 Trillion Market Cap; Bitcoin Surges $87K, While Ethereum Stood At $3k

Following Donald Trump's presidential election victory, the cryptocurrency market surged, reaching a whopping $3.02...
00:02:30

VIDEO: Israeli PM Netanyahu Visits Lebanese Border, Promises Strong Action Against Hezbollah

During a recent visit to the Lebanese border, Israel's Prime Minister Benjamin Netanyahu highlighted...
00:01:45

“I Will End the War in Gaza,” Kamala Harris to Arab American Community

In a final bid to win over Arab American voters in the closing stages...

FULL SPEECH: Cardi B Addresses Kamala Harris Rally In Wisconsin

Singer Cardi B addressed a rally in Milwaukee, Wisconsin, showing her support for presidential...

Finzilo Review | 8 Trading Features That Make Finzilo Stand Out

When it comes to online trading platforms, choosing the right one can significantly impact...

Vehant Technologies’ Shailendra Kumar Singh On Leveraging AI To Tackle India’s Traffic Challenges

During an interview with our editorial team, Shailendra Kumar Singh, Business Unit Head ,...
00:00:00

United Nations Security Council Holds Meeting On Israel Middle East Situation

UN LIVE: Members of the United Nations Security Council meet to discuss the Israel...

TVS Motor Achieves Highest Ever Revenue and Profits in Q2

TVS Motor Company posts highest ever operating revenue of Rs. 9,228 Crores registering a...

Live From Parliament: UK Deputy PM Angela Rayner takes PMQs

London News: The United Kingdom (UK) deputy prime minister Angela Rayner takes questions from...

Tom Homan Old Video Goes Viral, After Donald Trump Taps Him As Border Czar

An old video of Tom Homan, former acting head of US Immigration and Customs...

Protests Erupts in Valencia Over Deadly Floods in Eastern Spain

Over ten thousand people took to the streets of Valencia to protest against the...

Why BITBinvest.com is Expanding Worldwide & Capturing High-Profile Trader’s Attention?

BITBinvest.com has rapidly emerged as one of the leading companies in online trading, making...

4 Key Ways Robotics May Change Warehouse Operations by 2030

The landscape of warehouse operations is poised for significant transformation by 2030 with the...

LTC UPDATE: Gate io Lists Litecoin Under Meme Coins

US-based cryptocurrency exchange platform Gate.io has listed Litecoin (LTC) under its meme coin category. The...

United Nations Security Council Holds Meeting On Israel Middle East Situation

UN LIVE: Members of the United Nations Security Council meet to discuss the Israel...

Russian Producers Ready to Increase Fertilizer Supplies to India

Moscow, Russia: Russian companies are ready to increase fertilizer supplies to India, but the...

TVS Motor Achieves Highest Ever Revenue and Profits in Q2

TVS Motor Company posts highest ever operating revenue of Rs. 9,228 Crores registering a...