StrongPity APT group targets Android users with trojanized Telegram app: ESET Research

Date:

Trending

ESET researchers identified an active StrongPity APT group campaign leveraging a fully functional but trojanized version of the legitimate Telegram app, which despite being non-existent, has been repackaged as the Shagle app.

- Advertisement -

This StrongPity backdoor has various spying features: it is 11 dynamically triggered modules that are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs, and contact lists, and much more. These modules are being published publicly for the first time.

If the victim grants the malicious StrongPity app notification access and accessibility services, the app will also have access to incoming notifications from 17 apps such as Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communication from other apps. The campaign is likely very narrowly targeted since ESET telemetry still hasn’t identified any victims.

- Advertisement -

Unlike the entirely web-based, genuine Shagle site, which doesn’t offer an official mobile app to access its services, the copycat site only provides an Android app to download, with no web-based streaming possible. This trojanized Telegram app has never been made available in the Google Play store.

The malicious code, its functionality, class names, and the certificate used to sign the APK file are identical to the previous campaign; thus ESET believes with high confidence that this operation belongs to the StrongPity group. Code analysis revealed that the backdoor is modular and additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to fit the campaign requests when operated by the StrongPity group.

“During our research, the analyzed version of malware available from the copycat website was not active anymore and it was no longer possible to successfully install and trigger its backdoor functionality. This is because StrongPity hasn’t obtained its API ID for its trojanized Telegram app. But that might change at any time should the threat actor decide to update the malicious app,” says Lukáš Štefanko, the ESET researcher who analyzed the trojanized Telegram app.

The repackaged version of Telegram uses the same package name as the legitimate Telegram app. Package names are supposed to be unique IDs for each Android app and must be unique on any given device. This means that if the official Telegram app is already installed on the device of a potential victim, then this backdoored version can’t be installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” adds Štefanko.

StrongPity’s app should have worked just as the official version does for communication, using standard APIs that are well documented on the Telegram website, but it no longer does. Compared to the first StrongPity malware discovered for mobile, this StrongPity backdoor has extended spying features. It is able to spy on incoming notifications and exfiltrate chat communication if the victim grants the app notification access and activates accessibility services.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

The Ultimate Guide to Choosing and Using Fonts in Your Design Projects

Fonts play a crucial role in every design project, from branding and web design to print media and beyond. Whether you’re a beginner just...

Predictive Analytics: The Key to Supply Chain Resilience

In today’s interconnected global economy, supply chains are the lifeblood of businesses, weaving intricate networks that span continents, industries, and suppliers. Yet, these networks are inherently vulnerable. For too long, supply chain risk management has been a reactive endeavor—a frantic response to disruptions triggered...

Empowering Growth: Boosting the Robotics Sector with Targeted Support

India's robotics sector is emerging as a key area of technological progress, driving innovation...

Software and Technology Changing the Industry

The advent of software and technological advancements has been a game-changer across various industries....
00:02:53

Canada, Australia Partner to Build $6 Bn Arctic Radar System

In a bid to enhance Arctic and national security, Canada's Prime Minister Mark Carney...

Meta Chief Legal Officer Jennifer Newstead Offloads Shares as Part of Trading Plan

According to regulatory filings, Jennifer Newstead, Chief Legal Officer at Meta Platforms, Inc. (NASDAQ:...

Alphabet Board Member Frances Arnold Increases Stake Following Dividend Allocation

According to a recent regulatory filing, Frances Arnold, a board member at Alphabet Inc.,...

Alphabet COA Amie Thuener O’Toole Increases Stock Holdings

In a filing with the U.S. Securities and Exchange Commission (SEC), Alphabet Inc.’s (NASDAQ...

Jensen Huang Offloads $49.8Mn in Nvidia Shares

Nvidia (NASDAQ: NVDA) CEO and President Jen-Hsun Huang has disclosed the sale of 431,611 company shares, valued at $49.8 million. According to a regulatory filing...

Elon Musk’s X Sues Indian Govt Over Content Regulation Clash

X Corp, an Elon Musk-owned social media firm, sued the Indian government in the...

Why Smart Cities Are the Future of Water Conservation

Water conservation has become an important factor due to climate change and worsened water...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding...

Alphabet CEO Sundar Pichai Increases Stocks Holdings Amid Dividend Adjustment

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Alphabet...

Layer PR Wins SME News UK Awards, Expands to Bengaluru

Layer PR, a global public relations firm owned by TechGraph, has secured two major awards at the SME News UK Awards as "Most Innovative...

Google Acquires Wiz for $32 Billion in All-Cash Deal

Google LLC, a subsidiary of Alphabet Inc. (NASDAQ: GOOG, GOOGL) has signed a deal to buy Wiz, a New York-based cloud security company, for $32 billion in an all-cash deal. The deal, which needs regulatory approval and standard closing conditions, will bring Wiz into Google...

The Sustainability Imperative: How IT Distribution Is Driving Green Tech Adoption

In today's day and time sustainability is no longer just a corporate commitment, it...

The Future of Digital Payments and Cybersecurity Challenges

The future of digital payments is evolving rapidly, driven by technological advancements, changes in...

The Role of Edge Computing in AI-Powered Cloud Solutions

With businesses including artificial intelligence (AI) in their operations, cloud computing has grown in...

From Startup to Success: Essential Steps for Landscaping Entrepreneurs

Starting a landscaping business is so exciting, blending creativity with the reward of transforming...

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and...

Trump Defends Elon Musk Plan for Federal Job Cuts; Govt Spending ‘Bloated’

Following a meeting with Elon Musk and senior cabinet members, U.S. President Donald Trump...

Demand for plumbers in Oman: which specialists are most in demand?

The demand for skilled plumbers in Oman is steadily increasing due to the country's...

Meta Executive Chris Cox to Sell $13.5 Million in Shares

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox has filed to sell 20,000...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding...

How a Money Back Policy Can Be a Smart Financial Choice?

Creating financial security involves strategic planning because investment decisions form one of the essential...

“We Are Not America”: Canada’s New PM Mark Carney On Trump’s Comment On Making it 51st state

In his first public remarks, Canada's New Prime Minister, Mark Carney, reaffirmed Canada's independence...
00:01:37

UK PM Kier Starmer Abolishes NHS England To Bring Health Services Under Govt Control

British Prime Minister Keir Starmer has announced plans to abolish NHS England and bring...
00:01:09

VIDEO: US President Donald Trump Calls NBC A ‘Worst Network’ On Television

During a press meeting at the Oval Office on Wednesday, US President Donald Trump...

Alphabet CEO Sundar Pichai Increases Stocks Holdings Amid Dividend Adjustment

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Alphabet...

Meta Executive Chris Cox to Sell $13.5 Million in Shares

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox has filed to sell 20,000...

Logistic Startup Picckup Secures $500K in Seed Funding to Expand Electric Fleet

A Mohali-based mid-mile and last-mile logistic startup, Picckup, on Thursday, raised $500K in series...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages,...