CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

StrongPity Hackers Distribute Trojanized Telegram App to Target Android Users

admin by admin
January 10, 2023
in Information Security


Jan 10, 2023Ravie LakshmananAdvanced Persistent Threat

The advanced persistent threat (APT) group known as StrongPity has targeted Android users with a trojanized version of the Telegram app through a fake website that impersonates a video chat service called Shagle.

“A copycat website, mimicking the Shagle service, is used to distribute StrongPity’s mobile backdoor app,” ESET malware researcher Lukáš Štefanko said in a technical report. “The app is a modified version of the open source Telegram app, repackaged with StrongPity backdoor code.”

StrongPity, also known by the names APT-C-41 and Promethium, is a cyberespionage group active since at least 2012, with a majority of its operations focused on Syria and Turkey. The existence of the group was first publicly reported by Kaspersky in October 2016.

The threat actor’s campaigns have since expanded to encompass more targets across Africa, Asia, Europe, and North America, with the intrusions leveraging watering hole attacks and phishing messages to activate the killchain.

One of the main hallmarks of StrongPity is its use of counterfeit websites that purport to offer a wide variety of software tools, only to trick victims into downloading tainted versions of legitimate apps.

In December 2021, Minerva Labs disclosed a three-stage attack sequence stemming from the execution of a seemingly benign Notepad++ setup file to ultimately deliver a backdoor onto infected hosts.

That same year, StrongPity was observed deploying a piece of Android malware for the first time by possibly breaking into the Syrian e-government portal and replacing the official Android APK file with a rogue counterpart.

The latest findings from ESET highlight a similar modus operandi that’s engineered to distribute an updated version of the Android backdoor payload, which is equipped to record phone calls, track device locations, and collect SMS messages, call logs, contacts lists, and files.

In addition, granting the malware accessibility services permissions enables it to siphon incoming notifications and messages from various apps like Gmail, Instagram, Kik, LINE, Messenger, Skype, Snapchat, Telegram, Tinder, Twitter, Viber, and WeChat.

The Slovak cybersecurity company described the implant as modular and capable of downloading additional components from a remote command-and-control (C2) server so as to accommodate the evolving objectives of StrongPity’s campaigns.

The backdoor functionality is concealed within a legitimate version of Telegram’s Android app that was available for download around February 25, 2022. That said, the bogus Shagle website is no longer active, although indications are that the activity is “very narrowly targeted” due to the lack of telemetry data.

There is also no evidence the app was published on the official Google Play Store. It’s currently not known how the potential victims are lured to the fake website, and if it entails techniques like social engineering, search engine poisoning, or fraudulent ads.

There is also no evidence the app (“video.apk“) was published on the official Google Play Store. It’s currently not known how the potential victims are lured to the fake website, and if it entails techniques like social engineering, search engine poisoning, or fraudulent ads.

“The malicious domain was registered on the same day, so the copycat site and the fake Shagle app may have been available for download since that date,” Štefanko pointed out.

Another notable aspect of the attack is that the tampered version of Telegram uses the same package name as the genuine Telegram app, meaning the backdoored variant cannot be installed on a device that already has Telegram installed.

“This might mean one of two things – either the threat actor first communicates with potential victims and pushes them to uninstall Telegram from their devices if it is installed, or the campaign focuses on countries where Telegram usage is rare for communication,” Štefanko said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

10 CXOs Share Their Powerful Leadership Lessons for Digital Trailblazers

Next Post

Initiateinquiries

Related Posts

Information Security

New Android Banking Trojan Targeting Brazilian Financial Institutions

by admin
February 4, 2023
Information Security

Fall 2022 PCI DSS report available with six services added to compliance scope

by admin
February 4, 2023
Information Security

Is Your EV Charging Station Safe? New Security Vulnerabilities Uncovered

by admin
February 3, 2023
Information Security

How to improve security incident investigations using Amazon Detective finding groups

by admin
February 3, 2023
Information Security

New Russian-Backed Gamaredon’s Spyware Variants Targeting Ukrainian Authorities

by admin
February 2, 2023
Next Post

Initiateinquiries

Recommended

Initiativesofreinvention

February 4, 2023

New Android Banking Trojan Targeting Brazilian Financial Institutions

February 4, 2023

Fall 2022 PCI DSS report available with six services added to compliance scope

February 4, 2023

Initiativesofnonlinearity ~ Future of CIO

February 3, 2023

Is Your EV Charging Station Safe? New Security Vulnerabilities Uncovered

February 3, 2023

How to improve security incident investigations using Amazon Detective finding groups

February 3, 2023

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 CIO News Hubb All rights reserved.