A sophisticated malware campaign has emerged, leveraging 607 malicious domains to distribute weaponized Android applications masquerading as Telegram Messenger.
This large-scale operation represents a significant escalation in mobile malware distribution, targeting users across multiple regions through carefully crafted phishing infrastructure.
The malicious domains, primarily hosted in Chinese language, utilize typosquatting techniques with variations like “teleqram,” “telegramapp,” and “apktelegram” to deceive unsuspecting users.
The attack vector begins with QR codes hosted on these domains, which redirect victims to zifeiji[.]asia, a convincingly designed fake Telegram website complete with official-looking favicon, downloadable APK, and authentic theme styling.
This centralized redirection mechanism allows attackers to maintain control over the distribution process while appearing legitimate to potential victims.
The malicious APK files, ranging from 60MB to 70MB in size, are distributed with hash values including MD5 signatures acff2bf000f2a53f7f02def2f105c196 and efddc2dddc849517a06b89095b344647.
Bfore.AI analysts identified this campaign through their PreCrime™ Labs threat research division, revealing the operation’s extensive reach across multiple top-level domains.
The most frequently utilized domains include .com (316 instances), .top (87 instances), and .xyz (59 instances), all registered through the Gname registrar.
This distribution strategy maximizes the campaign’s resilience against takedown efforts while maintaining operational continuity.
The malware’s technical sophistication lies in its exploitation of the Janus vulnerability, specifically targeting Android devices running versions 5.0 through 8.0.
By utilizing v1 signature schemes, the malicious APK bypasses modern security restrictions and operates undetected on vulnerable devices.
The most concerning aspect of this malware involves its remote command execution capabilities through socket-based callbacks.
The malicious application establishes persistent connections with command-and-control servers, enabling real-time instruction reception and execution.
This functionality is achieved through MediaPlayer invocation combined with cleartext traffic protocols including HTTP and FTP, deliberately bypassing secure transmission standards.
The malware requests extensive permissions including READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE, granting attackers comprehensive access to user data.
Additionally, a JavaScript tracking script hosted at telegramt.net/static/js/ajs.js?v=3 collects device information and browser data, forwarding this intelligence to dszb77[.]com for analysis and user behavior tracking.
Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…