Categories: Techno

New virus for Android operating system disguises itself as Telegram messenger and steals user data

Specialists from the information security company Cyfirma have discovered a new malware called FireScam, which is aimed at stealing data from Android users. The malware masquerades as a fake Telegram Premium app and is distributed via a page on GitHub.

According to researchers from Cyfirma, an APK dropper protected from detection by Android security tools was delivered to the victim's device via a malicious page. It received the permissions necessary to scan the device for installed applications, as well as access to the device's storage and permission to download additional packages. The module then extracted and installed the main malware Telegram_Premium.apk, which in turn requested permission to monitor messages, clipboard data, SMS content, etc.

When first launched, the virus displays a data entry page similar to the one seen when logging into Telegram. The data entered by the user is stolen and then used to work with the messenger. FireScam also establishes a connection to the Firebase Realtime Database, where information stolen from the victim's device is transferred. According to Cyfirma, the stolen data is stored in the database temporarily, and after the attackers filter it, it is deleted or transferred to another location.

The virus also establishes a permanent connection to a remote server, which allows attackers to execute various commands on the victim's device, including requesting certain data, setting additional tracking parameters, and downloading additional malicious software. FireScam is able to track changes in activity on the device's screen, recording various events lasting more than 1000 ms. The virus carefully monitors all transactions, trying to intercept the victim's confidential payment data. Everything that the user types and copies to the clipboard is classified and transmitted to a remote server.

While Cyfirma has no guesses as to who is the operator of the new malware, the company noted that the campaign is a «sophisticated and multi-layered threat» that «uses advanced masking techniques». The company's specialists recommend that users be cautious about files they download from potentially unreliable sources.

Natasha Kumar

Natasha Kumar has been a reporter on the news desk since 2018. Before that she wrote about young adolescence and family dynamics for Styles and was the legal affairs correspondent for the Metro desk. Before joining The Times Hub, Natasha Kumar worked as a staff writer at the Village Voice and a freelancer for Newsday, The Wall Street Journal, GQ and Mirabella. To get in touch, contact me through my natasha@thetimeshub.in 1-800-268-7116

Share
Published by
Natasha Kumar

Recent Posts

Destruction of independence, repression, capture of the media by the authorities – report to the Council of Europe on the state of journalism

< img src = "/uploads/blogs/7a/48/ib-fqokkt02G_6240df4a.jpg" Alt = "Destruction of independence, repression, capture of the media-a…

43 minutes ago

The Russian Federation stands for hybrid attacks on Romania during the presidential election – Italian special service

< img src = "/uploads/blogs/09/83/ib-fqo9u7c98_df4A499e.jpg" Alt = "Russia stands for hybrid attacks on Romania during…

43 minutes ago

French Satellite Satellite Operator Eutelsat plans to replace Starlink in Ukraine

< img src = "/uploads/blogs/6b/be/ib-fqosoqbul_046a48c3.jpg" Alt = "French Satellite Satellite Operator plans to replace Starlink…

2 hours ago

Apple has first lowered the starting price of a new MacBook Air

< img src = "/uploads/blogs/ff/ef/ib-fqosiojp5_68271dbd.jpg" Alt = "Apple first reduced the starting price of the…

2 hours ago

Solana co -founder skeptically spoke about the cryptocurrency in the United States

< img src = "/uploads/blogs/4e/85/ib-fqospf6r8_ea2a6bb1.jpg" Alt = "Solana co-founder was skeptical about cryptorester in the…

3 hours ago

With Brain2qwerty, Meta wants to read in the brains

< IMG LOADING = "Lazy" SRSC = "/Sites/Default/Files/Styles/Medium/2016-12/MUSEE_CERVEAU-PEROU-LIMA-FRANCESOIR.JPG ? Itok = XWCE28V5" Width = "1300"…

4 hours ago