Malicious Android apps – Telegram clones – have been found on Google Play with more than 60,000 downloads, infecting people with spyware. This spyware is capable of stealing users’ messages, contact lists and other important data. The campaign has been codenamed Evil Telegram by Russian cybersecurity Kaspersky.

It appears that the apps have been customized for Chinese- speaking users who belong to the Uyghur ethnic minority.
These apps were discovered by Kaspersky and reported to Google. However, when the researchers published their report, several malicious apps were still available for download through Google Play.
See also: iMessage: Zero-click exploit infects iPhones with spyware
Trojanized Telegram apps
The Telegram apps featured in Kaspersky's report are presented as alternatives that are "faster" than the regular app.
According to security, the spyware applications are identical to Telegram, but contain additional functions in the code that are used to steal data.
Specifically, there is an additional package named “com. wsys” that gains access to the user's contacts, while also collecting the victim's username, user ID, and phone number.
When the user receives a message on the trojanised Telegram app, the spyware sends a copy directly to the operator's command and control (C2) server at “sg[.]telegrnm[.]org”.
The data sent to the attackers contains contents message, the title and chat/channel ID, as well as the sender's name and ID.
See also: North Korean hackers target security researchers using zero-day bug

The spyware also monitors for changes to the victim's username and ID, and for changes to the contact. If it notices a change, it will collect the latest information.
The malicious Telegram apps used the package names “org.telegram.messenger.wab” and “org.telegram.messenger.wob”, while the legitimate Telegram app uses “org.telegram.messenger.web”.
Following the researchers' report, Google removed the spyware apps from Google Play and shared the following statement with BleepingComputer.
“We take app security and privacy allegations seriously , and if we find that an app has violated our policies, we take appropriate action. All reported apps have been removed from Google Play and the developers have been blocked. Users are also protected by Google Play Protect, which can warn users or block apps known to be malicious on Android devices with Google Play Services.“.
Cybercriminals often create clones of popular apps to trick users into breaking into devices . Late last month, ESET warned about two trojanized messaging apps, Signal Plus Messenger and FlyGram, that mimicked Signal and Telegram but purported to be more feature-rich versions.
See also: Mirai botnet: New version infects Android TV boxes for profit

These apps were removed from both Google Play and the Samsung Galaxy Store. They contained the BadBazaar malware , which allows its operators (the Chinese APT “GREF”) to spy on their targets.
To avoid malware /spyware infection , it is important to download genuine versions of apps to your device and avoid downloading apps that look like the originals but promise improved privacy, speed, or other features.
Android malware/spyware is an ever-growing threat. As smartphones become more powerful, they also become more attractive targets for cybercriminals. It's important to stay vigilant and stay informed about how to protect your devices.
Source: www.bleepingcomputer.com
