logo

Telegram zero-day allowed sending malicious Android APKs as videos

ID: aadb8435-ce9c-50c7-8b77-467dc5efc3e8

STIX ID: report--aadb8435-ce9c-50c7-8b77-467dc5efc3e8

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-07-22

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A Telegram for Android zero-day dubbed "EvilVideo" let attackers craft APKs that appeared as 30-second video files; ESET obtained a PoC, identified a C2 (infinityhackscharan.ddns.net) and malicious APKs on VirusTotal, and responsibly disclosed the flaw. Telegram patched the issue in v10.14.5 (July 11, 2024); the attack requires several user actions (tap preview, open external player, enable unknown app installs), which reduces risk despite a reported five-week window where actors could have exploited the bug.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.