Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Telegram Messenger Abused by Android Malware to Seize Full Device Control

Security researchers at Doctor Web have identified a sophisticated Android backdoor masquerading as Telegram X, which provides cybercriminals with complete control over victims' accounts and devices.

Security researchers at Doctor Web have identified a sophisticated Android backdoor masquerading as Telegram X, which provides cybercriminals with complete control over victims' accounts and devices.

The malware, identified as Android.Backdoor.Baohuo.1.origin, has infected over 58,000 devices globally, with approximately 20,000 active infections currently being monitored.

This threat signifies a significant advancement in mobile malware capabilities, integrating Redis database for control—a technique previously undocumented in Android threats.

The backdoor spreads through malicious websites disguised as app catalogs, where users are enticed by fake advertisements promising dating and video chat functionalities. Approximately 3,000 different models of smartphones, tablets, TV box sets, and cars with Android-based onboard computers have been infected.

The compromised versions of Telegram X are distributed on third-party app stores such as APKPure, ApkSum, and AndroidP, under the guise of the official Telegram developer, despite having different digital signatures from legitimate versions.

Approximately 3,000 different models of smartphones, tablets, TV box sets, and cars with Android-based onboard computers have been infected.
Eleanor Tate · Thehackingpost

Android.Backdoor.Baohuo.1.origin distinguishes itself by its ability to perform extensive account manipulation. It can hide unauthorized device connections from the victim’s active sessions list and autonomously manage Telegram channels and chats on the victim's behalf, concealing these actions entirely.

The backdoor operates through three modification variants: direct embedding in the messenger's main executable, dynamic loading via LSPatch tool injection, and others. Regardless of the deployment method, the malicious messenger remains fully functional, preventing user suspicion while allowing full control over messaging functionalities.

The command and control architecture introduces a new technique in the Android threat landscape by leveraging Redis database infrastructure for command delivery. This dual-channel system provides operational redundancy, reverting to standard C2 server communication if the Redis connection fails.

The backdoor extracts continuous data streams, including SMS messages, contact lists, and clipboard contents. The clipboard interception capability is particularly concerning, as it can capture sensitive information such as cryptocurrency wallet seeds and passwords.

Advertisement

Every three minutes, the malware uploads device permissions, screen status, and Telegram authentication credentials to attacker servers. Research indicates approximately 3,000 distinct Android devices have been compromised, spanning smartphones, tablets, television boxes, and vehicles with Android-based systems.

While Brazil and Indonesia are primary infection vectors, the global distribution highlights the threat's widespread reach and the sophisticated infrastructure supporting ongoing malware evolution.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories