Cyber Security News

Hackers Using 607 Malicious Domains to Deliver APK Malware That Enables Remote Command Execution

A sophisticated malware campaign has emerged, leveraging 607 malicious domains to distribute weaponized Android applications masquerading as Telegram Messenger.

This large-scale operation represents a significant escalation in mobile malware distribution, targeting users across multiple regions through carefully crafted phishing infrastructure.

The malicious domains, primarily hosted in Chinese language, utilize typosquatting techniques with variations like “teleqram,” “telegramapp,” and “apktelegram” to deceive unsuspecting users.

The attack vector begins with QR codes hosted on these domains, which redirect victims to zifeiji[.]asia, a convincingly designed fake Telegram website complete with official-looking favicon, downloadable APK, and authentic theme styling.

Telegram APK download site featured in Chinese language (Source – Bfore.ai)

This centralized redirection mechanism allows attackers to maintain control over the distribution process while appearing legitimate to potential victims.

The malicious APK files, ranging from 60MB to 70MB in size, are distributed with hash values including MD5 signatures acff2bf000f2a53f7f02def2f105c196 and efddc2dddc849517a06b89095b344647.

Bfore.AI analysts identified this campaign through their PreCrime™ Labs threat research division, revealing the operation’s extensive reach across multiple top-level domains.

The most frequently utilized domains include .com (316 instances), .top (87 instances), and .xyz (59 instances), all registered through the Gname registrar.

This distribution strategy maximizes the campaign’s resilience against takedown efforts while maintaining operational continuity.

The malware’s technical sophistication lies in its exploitation of the Janus vulnerability, specifically targeting Android devices running versions 5.0 through 8.0.

By utilizing v1 signature schemes, the malicious APK bypasses modern security restrictions and operates undetected on vulnerable devices.

Remote Command Execution Mechanism

The most concerning aspect of this malware involves its remote command execution capabilities through socket-based callbacks.

The malicious application establishes persistent connections with command-and-control servers, enabling real-time instruction reception and execution.

This functionality is achieved through MediaPlayer invocation combined with cleartext traffic protocols including HTTP and FTP, deliberately bypassing secure transmission standards.

The malware requests extensive permissions including READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE, granting attackers comprehensive access to user data.

Additionally, a JavaScript tracking script hosted at telegramt.net/static/js/ajs.js?v=3 collects device information and browser data, forwarding this intelligence to dszb77[.]com for analysis and user behavior tracking.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago