HomeAppsStrongPity APT group targets Android users with trojanized Telegram app: ESET Research

StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Most Read

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

- Advertisement -

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

Subscribe To Morning Newsletters

Sign up to receive the latest news stories, exclusive interviews, and more in your inbox.

We don’t spam! Read our privacy policy for more info.

Editor's Pick

Krishna Mali
Krishna Mali
Founder, CEO & Group Editor of TechGraph.

Read More Stories

SKF Showcases Intelligent & Clean Solutions for the Textile Industry at International Textile Machinery Exhibition (ITME) 2022

SKF India, the country's leading technology and solutions provider of bearings and services will showcase innovative products and solutions...

OneRare and Cornitos: Bringing the Magic of Cornitos to the Foodverse

Cornitos is a leader in the Snack category and has always strived to give its fans and patrons the...

Chitkara University Signs MoU with NEC Corporation India to Transform Learning in the Field of AI/ML

Chitkara University announced its collaboration with NEC Corporation India, a wholly owned subsidiary of NEC Corporation, for a comprehensive...

Role of skills-based hiring in promoting inclusive economic growth in India

In recent years, India's employment landscape has experienced a profound shift, with an increasing emphasis on skills-based hiring. This...

Global Cryptocurrency Regulations: Impact on Industry and Investor Behavior in 2024

The world of cryptocurrency has seen remarkable growth and evolution since its inception, transitioning from obscure digital assets to...

Interview: Modernizing Field Sales Operations With Delta Sales App Director Ekta Golchha

Speaking with TechGraph, Ekta Golchha, Founder and Director of Delta Sales App underscores the app's innovative role in optimizing...