The malicious software Triada infects Android devices via a fake Telegram application.
Fortunately, the infected version of Telegram that carries the malicious Triada software is distributed through third‑party stores rather than the official Google Play Store.
The malicious version of the Telegram app that contains Triada is cleverly disguised as the latest version of Telegram Messenger, specifically version 9.2.1.
See also: RomCom: Targets NATO summit participants in phishing attacks

Recent research by Check Point Software Technologies highlights a worrying trend: a fake Telegram messenger app infects Android devices with malware upon installation. It is crucial to know that, unlike other malicious apps, this app cannot be found in the Google Play Store, but in third-party app stores.
Given the widespread popularity of Telegram as one of the most frequently used messaging applications worldwide, it is not surprising that scammers and cybercriminals have targeted it for their malicious activities.
The malicious Telegram app works by gaining system privilege escalation to launch the malware. This can be achieved if the user grants phone permissions during the sign-up process. Once this access is granted, the malware can seamlessly insert itself into other processes, allowing it to perform a range of malicious activities.
See also: E-commerce companies: They hire professionals to deal with increasedfraud

It is important to emphasize that previous research into Triada has already demonstrated its resilience, with Google confirming the presence of this malware on low-cost Android phones.
Αυτές οι επηρεαζόμενες συσκευές περιλαμβάνουν μοντέλα από διάφορες εταιρείες, όπως οι Leagoo, ARK Benefit, Zopo Speed, Doogee, Cherry Mobile Flare και αρκετές άλλες. Αυτό υπογραμμίζει περαιτέρω την ανάγκη για επαγρύπνηση και μέτρα ασφαλείας, καθώς η εμβέλεια της Triada έχει επεκταθεί σε ένα ευρύ φάσμα συσκευών στην αγορά.
In a report shared with Hackread.com, Checkpoint researchers described the various functions that the Triada malware can perform. These include signing up victims for multiple paid subscriptions, displaying invisible and background ads, and making unauthorized in-app purchases using SMS and phone numbers. In addition, Triada has the ability to steal sensitive data, such as passwords, from compromised devices.
Information source: hackread.com
