logo

New FireScam Android data-theft malware poses as Telegram Premium app

ID: 161f7e68-8773-5a53-bf0c-2bf0c0a7e64b

STIX ID: report--161f7e68-8773-5a53-bf0c-2bf0c0a7e64b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-04

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A new Android malware called 'FireScam' is being distributed through GitHub-hosted phishing pages that mimic Russia's RuStore; a DexGuard-obfuscated dropper (GetAppsRu.apk) installs a Telegram-themed payload which steals credentials via a fake WebView, monitors clipboard/SMS/telephony and screen activity, captures financial input, and exfiltrates data to a Firebase Realtime Database while maintaining a WebSocket-based C2 for real-time commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.