Altered Telegram App Steals Chinese Users' Android Data
ID: 012e53cb-316d-5903-9d96-a5e6527330da
STIX ID: report--012e53cb-316d-5903-9d96-a5e6527330da
Feed Name: Dark Reading
A threat actor is running a large-scale phishing and SEO-driven campaign targeting Chinese-speaking users in the Asia-Pacific region by hosting over 600 typosquatted domains that distribute a Trojanized Telegram Android APK. The malicious APKs are repackaged using Android's legacy v1 signature to exploit the Janus vulnerability (affecting Android 5.0–8.0), enabling hidden payloads and remote-control capabilities via the Android Media Player and a Firebase backend; defenders are advised to block untrusted domains, use threat intelligence/EDR to detect the APKs, and prevent installs from unverified sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
