FireScam Android Spyware Campaign Poses 'Significant Threat Worldwide'
ID: 8eb4c141-197b-5ee2-80b4-ed5b9fec4e22
STIX ID: report--8eb4c141-197b-5ee2-80b4-ed5b9fec4e22
Feed Name: Dark Reading
Date Published: 2025-01-06
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
FireScam is a recently observed Android spyware/infostealer campaign that lures victims via a phishing site impersonating an app store to install a fake Telegram Premium app; once installed it steals notifications, messages and other sensitive data, uses Firebase Realtime Database for exfiltration and C2, and maintains persistence to deliver additional malware. Researchers highlight that the campaign abuses legitimate services and common apps to evade detection and recommend real-time mobile app scanning, API protections, and reliance on platform defenses like Google Play Protect.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
