logo

Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control

ID: afea31bc-280f-57c3-b877-83e33acefb62

STIX ID: report--afea31bc-280f-57c3-b877-83e33acefb62

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-10-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Android.Backdoor.Baohuo.1.origin is a sophisticated Android backdoor distributed via fake websites and third‑party app stores as a trojanized Telegram X; it has infected roughly 58,000 devices (including phones, tablets, TV boxes and Android vehicle systems), primarily targeting Brazil and Indonesia. The backdoor exfiltrates credentials, chat histories, SMS, contacts and clipboard contents; hides unauthorized sessions and manipulates channels to inflate subscribers; and notably uses Redis as a command‑and‑control channel alongside traditional C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.