logo

Attackers Exploit 'EvilVideo' Telegram Zero-Day to Hide Malware

ID: c0494164-99e8-5156-abe3-ed5fd356853c

STIX ID: report--c0494164-99e8-5156-abe3-ed5fd356853c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-23

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

ESET researchers discovered a zero-day "EvilVideo" vulnerability in Telegram for Android (<= 10.14.4) that allowed attackers to upload crafted multimedia which rendered as a video preview but contained an Android payload; when a user attempted to play the video and chose to open it in an external player, they could be prompted to install malware. Telegram issued a server-side fix for 10.14.5+, ESET published IoCs on GitHub, and users are advised to update and avoid opening unsolicited media.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.