logo

Baohuo Android Malware Hijacks Telegram Accounts via Fake Telegram X

ID: 9e4bf6fc-ffb1-5343-aca8-a5bd9838b4ac

STIX ID: report--9e4bf6fc-ffb1-5343-aca8-a5bd9838b4ac

Feed Name: HackRead

Threat Score
75/100

Date Published: 2025-10-24

Date Updated: 2026-04-22

Author: Waqas

...
...

A new Android backdoor, Android.Backdoor.Baohuo.1.origin, is being distributed via fake Telegram X apps and malicious ads; it uses Xposed-based runtime hooking and a novel Redis-backed command-and-control channel to take over Telegram accounts, hide unauthorized activity, and exfiltrate clipboard data, SMS, contacts and device details. Doctor Web reports over 58,000 infected devices across multiple countries (notably India, Brazil and Indonesia) and finds trojanized packages on third-party app stores, urging users to install Telegram only from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.