Attackers Exploit 'EvilVideo' Telegram Zero-Day to Hide Malware
ID: c0494164-99e8-5156-abe3-ed5fd356853c
STIX ID: report--c0494164-99e8-5156-abe3-ed5fd356853c
Feed Name: Dark Reading
Date Published: 2024-07-23
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
ESET researchers discovered a zero-day "EvilVideo" vulnerability in Telegram for Android (<= 10.14.4) that allowed attackers to upload crafted multimedia which rendered as a video preview but contained an Android payload; when a user attempted to play the video and chose to open it in an external player, they could be prompted to install malware. Telegram issued a server-side fix for 10.14.5+, ESET published IoCs on GitHub, and users are advised to update and avoid opening unsolicited media.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
