BadBazaar espionage tool targets Android users via trojanized Signal and Telegram apps
ID: da5b6d73-2da7-5521-86bb-3023a22a219c
STIX ID: report--da5b6d73-2da7-5521-86bb-3023a22a219c
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET Research uncovered two active Android campaigns (Signal Plus Messenger and FlyGram) distributing BadBazaar spyware via Google Play, Samsung Galaxy Store and websites; the trojanized apps exfiltrate device data, contacts, call logs and Google accounts, and uniquely enable silent linking of Signal devices and remote Telegram backups—attributed to the China-aligned GREF cluster and supported by IoCs and network telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
