News Heading

China-Linked Android Spyware Targets Telegram and Signal Users in Europe and the US

Reading time: 2 min

  • Shipra Sanganeria

    Written by: Shipra Sanganeria Cybersecurity & Tech Writer

Cybersecurity researchers discovered trojanized Android apps for Signal and Telegram used in a new espionage campaign. The apps found on Google Play and Samsung Galaxy Store are said to contain the BadBazaar spyware, attributed to the Chinese APT group GREF.

According to ESET researcher Lukáš Štefanko, the campaign distributing the malware espionage code was most likely active since July 2020 and 2022, respectively. To infiltrate targeted victims’ devices, GREF is said to have used pathed versions of the open-source Signal and Telegram app for Android, named ‘Signal Plus Messenger’ and ‘FlyGram’.

The spyware was previously documented being used against Uyghurs and other Turkic ethnic minorities outside of China. ‘’Based on our research, [..] potential victims were also lured to install the FlyGram app from a Uyghur Telegram group focused on Android app sharing, which now has more than 1,300 members,’’ Lukáš stated.

This time however, ESET found that the campaign was primarily targeted at users in Australia, Brazil, Denmark, the Democratic Republic of the Congo, Germany, Hong Kong, Hungary, Lithuania, the Netherlands, Poland, Portugal, Singapore, Spain, Ukraine, the US, and Yemen.

The espionage malware BadBazaar has the capability to extract device information, including contact and installed apps list, steal call logs and messages, Google accounts, remotely using the device camera to take pictures, transferring Telegram communication to an attacker controlled C2 server, and linking devices via the Signal Plus Messenger app.

Before the discovery of their malicious capability, the apps had been downloaded and installed over a hundred times. Based on the available data of Play Store, the apps:

  • Signal Plus Messenger – installed 100+ times since July 2022, The app is also available for download via signalplus[.]org
  • FlyGram – installed 5,000+ times since June 2020. The app is also available for download via flygram[.]org

When notified, Google removed both the apps from the Play Store, but they continue to be available on Samsung Galaxy Store.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!
5.00 Voted by 1 users
Title
Comment
Thanks for your feedback
Please wait 5 minutes before posting another comment.
Comment sent for approval.

Leave a Comment

Show more...