logo

Altered Telegram App Steals Chinese Users' Android Data

ID: 012e53cb-316d-5903-9d96-a5e6527330da

STIX ID: report--012e53cb-316d-5903-9d96-a5e6527330da

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-07-16

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

A threat actor is running a large-scale phishing and SEO-driven campaign targeting Chinese-speaking users in the Asia-Pacific region by hosting over 600 typosquatted domains that distribute a Trojanized Telegram Android APK. The malicious APKs are repackaged using Android's legacy v1 signature to exploit the Janus vulnerability (affecting Android 5.0–8.0), enabling hidden payloads and remote-control capabilities via the Android Media Player and a Firebase backend; defenders are advised to block untrusted domains, use threat intelligence/EDR to detect the APKs, and prevent installs from unverified sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.