Trojanized Signal and Telegram apps , containing the BadBazaar spyware , were uploaded to Google Play and the Samsung Galaxy Store by the Chinese hacking group known as GREF .

This malware has previously been used to attack ethnic minorities in China. However, according to ESET, attackers are now targeting users in countries including Ukraine, Poland, the Netherlands, Spain, Portugal, Germany, HongKong, and the United States.
The capabilities of BadBazaar spyware include tracking the exact location of the device, stealing logs call SMS, recording phone calls, taking photos from the camera, stealing contact lists, files or databases.
The trojanized applications containing the BadBazaar malicious code were discovered by ESET researcher Lukas Stefanko.
See also: Paramount Global: Announces data breach
Trojanized IM applications
The Chinese group's two apps are called "Signal Plus Messenger" and "FlyGram", and are patched versions of the popular open-source IM apps Signal and Telegram.
In fact, hackers have created special websites at “signalplus[.]org” and “flygram[.]org” to make the apps look more legitimate. There are also links available to install the app from Google Play or directly from the website.
ESET says that the FlyGram app targets sensitive data such as contact lists, call logs, Google Accounts, and WiFi data . It also has a dangerous backup function that sends Telegram communication data to a server controlled by attackers.
Analysis of available data shows that at least 13,953 FlyGram users have activated this backup. However, we do not know the exact number of users of the spyware application.
See also: VMware Aria: Vulnerable to critical SSH authentication bypass vulnerability
On the other hand, the Signal clone collects similar information, but focuses more on extracting information related to Signal, such as the victim's communications and the PIN that protects their account from unauthorized access.
However, the fake Signal app includes a feature that makes the attack more interesting, as it allows the attacker to link a victim's Signal accounts to devices controlled by them (the attackers), allowing them to view future messages.

Signal includes a QR-code-based feature that allows you to connect multiple devices to a single account, so messages are visible across all devices.
Signal Plus Messenger with BadBazaar spyware exploits this feature by bypassing the QR-code linking process and automatically linking its own devices to victims' Signal accounts without the victim. This allows attackers to monitor all future messages sent from the Signal account.
Essentially, the spyware secretly connects the smartphone to the attacker's device, allowing the attacker to spy on Signal communications without the victim knowing.
ESET says that this method of spying on Signal has been used in the past as it is the only way to obtain the content of messages.
To see if someone is logged into your Signal account, open the official Signal app and go to Settings. Then, tap on the “Linked Devices” option to view and manage all your linked devices.
See also: New Ransomed ransomware group uses a new extortion tactic
The spyware app FlyGram was uploaded to Google Play in July 2020 and removed on January 6, 2021, having accumulated a total of 5,000 installations (through this channel alone).
Signal Plus Messenger was uploaded to Google Play and the Samsung Galaxy store in July 2022 and Google removed it on May 23, 2023. It has only just been removed from the Samsung Galaxy Store.
Android users are advised to use the official versions of Signal and Telegram to be sure they are not at risk. Spyware infection can lead to serious breaches of user privacy and security , making its prevention and early detection essential.
Source: www.bleepingcomputer.com
