The malicious threat actor StrongPity has been discovered distributing a fraudulent copy of the Shagle chat app that hides a backdoor in its code. This trojanized version is based on the Telegram app for Android and carries additional threats to users' security.

Shagle is a secure, online video chat platform that connects strangers from all over the world. However, the platform is entirely web-based, which means there is no option for a mobile app.
See also: Puzzle trojan attack trains AI assistants to suggest malicious code
Since 2021, StrongPity has been exploiting a fake Shagle website to trick victims into downloading harmful Android apps. Once the malware is installed, cybercriminals can track their victims and gain access to critical data, such as phone calls, SMS messages, and contact information.
A brief recap of the StrongPity activity
Recently, ESET researchers discovered the latest StrongPity activity, which they attribute to an APT spyware group due to the similarity of the code to previous payloads. Additionally, BleepingComputer noticed that the Android app is signed by the same certificate that was used in 2021 to impersonate a Syrian government Android app. This is another example of how powerful and sophisticated these threat actors have become.
See also: MFHS: Hackers stole data from 460,000 people
Promethium, alias StrongPity or APT-C-41, has gained infamy due to its campaign that introduced malicious trojans into Notepad++ installers and WinRAR & TrueCrypt downloads with the aim of spreading malware.
Trojanized Android Telegram app
The StrongPity threat campaign spread a sneaky modified version of Telegram v7.5.0 (February 2022), hiding it in a malicious Android application titled “video.apk”.
As ESET reports, users are most likely to encounter the fake Shagle website through phishing emails and SMS messages. However, instead of being accessible on Google Play like legitimate apps, the malicious APKs can be downloaded directly from the spoofed website.
According to ESET researchers, the APK was likely circulating since November 2021, when the cloned website first appeared online. However, its presence was only detected in July 2022.
See also: Even the US government uses weak passwords
While using Telegram for the hacker group's fake app has its drawbacks, it is especially damaging if the victim already has a valid version of the app on their device. This means that, unfortunately, the backdoored alternative cannot be installed in this case.

The report states that, due to excessive usage, the API identifier used in the captured samples has been restricted, so the trojanized application will no longer accept new user registrations, thus the backdoor will not work.
According to the ESET report, the StrongPity group, which has been active since 2012, has continued to demonstrate its favorite tactic of disguising backdoors in legitimate software installers for an entire decade.
To avoid these malicious attacks, be careful when installing new apps on Android devices from sources other than Google Play.
Information source: heimdalsecurity.com
