Massive Spyware Outbreak Disguised as Fake Telegram Apps on Google Play
Fake Telegram apps with spyware capabilities have been discovered on the Google Play Store, aiming to steal sensitive information from Android devices. These malicious apps, dubbed "Evil Telegram" by cybersecurity firm Kaspersky, were responsible for collecting user data, including names, user IDs, contacts, phone numbers, and chat messages, and sending it to a server controlled by threat actors. These counterfeit apps had been downloaded millions of times before Google removed them.
To disguise themselves as legitimate Telegram apps, the spyware apps used package names like "wab," "wcb," and "wob," employing typosquatting techniques. While appearing as fully functional Telegram clones with localized interfaces, these fake versions contained an additional malicious module.
This revelation follows a recent report from ESET about the BadBazaar malware campaign, exploiting a fake Telegram version to target the official app marketplace. It highlights a growing trend of malicious actors using counterfeit communication apps for cyberattacks.
Source: https://thehackernews.com/2023/09/millions-infected-by-spyware-hidden-in.html