Telegram Messenger Abused by Android Malware to Seize Full Device Control
Security researchers at Doctor Web have identified a sophisticated Android backdoor masquerading as Telegram X, which provides cybercriminals with complete control over victims' accounts and devices.
Security researchers at Doctor Web have identified a sophisticated Android backdoor masquerading as Telegram X, which provides cybercriminals with complete control over victims' accounts and devices.
The malware, identified as Android.Backdoor.Baohuo.1.origin, has infected over 58,000 devices globally, with approximately 20,000 active infections currently being monitored.
This threat signifies a significant advancement in mobile malware capabilities, integrating Redis database for control—a technique previously undocumented in Android threats.
The backdoor spreads through malicious websites disguised as app catalogs, where users are enticed by fake advertisements promising dating and video chat functionalities. Approximately 3,000 different models of smartphones, tablets, TV box sets, and cars with Android-based onboard computers have been infected.
The compromised versions of Telegram X are distributed on third-party app stores such as APKPure, ApkSum, and AndroidP, under the guise of the official Telegram developer, despite having different digital signatures from legitimate versions.
Approximately 3,000 different models of smartphones, tablets, TV box sets, and cars with Android-based onboard computers have been infected.
Android.Backdoor.Baohuo.1.origin distinguishes itself by its ability to perform extensive account manipulation. It can hide unauthorized device connections from the victim’s active sessions list and autonomously manage Telegram channels and chats on the victim's behalf, concealing these actions entirely.
The backdoor operates through three modification variants: direct embedding in the messenger's main executable, dynamic loading via LSPatch tool injection, and others. Regardless of the deployment method, the malicious messenger remains fully functional, preventing user suspicion while allowing full control over messaging functionalities.
The command and control architecture introduces a new technique in the Android threat landscape by leveraging Redis database infrastructure for command delivery. This dual-channel system provides operational redundancy, reverting to standard C2 server communication if the Redis connection fails.
The backdoor extracts continuous data streams, including SMS messages, contact lists, and clipboard contents. The clipboard interception capability is particularly concerning, as it can capture sensitive information such as cryptocurrency wallet seeds and passwords.
Every three minutes, the malware uploads device permissions, screen status, and Telegram authentication credentials to attacker servers. Research indicates approximately 3,000 distinct Android devices have been compromised, spanning smartphones, tablets, television boxes, and vehicles with Android-based systems.
While Brazil and Indonesia are primary infection vectors, the global distribution highlights the threat's widespread reach and the sophisticated infrastructure supporting ongoing malware evolution.
Based on reporting by GBHackers.
