Cybersecurity researchers have uncovered a modified version of the popular Android messaging app Telegram, which was found to be malicious and capable of stealing data.

The malware within the malicious app can enroll the victim in various paid subscriptions, make in-app purchases, and steal login credentials, according to the mobile research team at cybersecurity firm Check Point.
The malicious app was detected and blocked by Harmony Mobile. Although it appeared innocent, this modified version was embedded with malicious code linked to the Triada Trojan.
“This Triada trojan, first detected in 2016, is a modular backdoor for Android that provides administrator privileges to download other malware,” the report said.
Modified versions of mobile apps may offer additional features and customizations, reduced prices, or be available in a wider range of countries compared to their original app.
Their offer may be attractive enough to entice naive users to install them via unofficial third-party app stores.
“The risk from installing modified versions comes from the fact that it is impossible for the user to know what changes have been made to the application code. To be more precise, it is unknown what code was added and whether it has malicious intent,” the team notes.
See also: Increase in the frequency of ransomware attacks without encryption in the last year
The malware disguises itself as Telegram Messenger version 9.2.1.
It has the same package name (org.telegram.messenger) and the same icon as the original Telegram app.
Upon launch, the user is taken to the Telegram authentication screen and asked to enter their device's phone number and give the app permission to access their phone.

The malware collects information about the device, creates a communication channel, downloads a configuration file, and waits to receive the payload from the remote server.
Its malicious capabilities include signing up the user for various paid subscriptions, making in-app purchases using the user's SMS and phone number, displaying ads (including invisible ads running in the background), and stealing login credentials, as well as other user and device information
See also: Ransomware attack hits Lebanese schools
“Always download your apps from trusted sources, whether it’s official websites or official app stores and repositories. Verify who the author and creator of the app is before downloading. You can read comments and reactions from previous users before downloading,” the team said.
Information source: siasat.com
