Categories: Techno

New virus for Android operating system disguises itself as Telegram messenger and steals user data

Specialists from the information security company Cyfirma have discovered a new malware called FireScam, which is aimed at stealing data from Android users. The malware masquerades as a fake Telegram Premium app and is distributed via a page on GitHub.

According to researchers from Cyfirma, an APK dropper protected from detection by Android security tools was delivered to the victim's device via a malicious page. It received the permissions necessary to scan the device for installed applications, as well as access to the device's storage and permission to download additional packages. The module then extracted and installed the main malware Telegram_Premium.apk, which in turn requested permission to monitor messages, clipboard data, SMS content, etc.

When first launched, the virus displays a data entry page similar to the one seen when logging into Telegram. The data entered by the user is stolen and then used to work with the messenger. FireScam also establishes a connection to the Firebase Realtime Database, where information stolen from the victim's device is transferred. According to Cyfirma, the stolen data is stored in the database temporarily, and after the attackers filter it, it is deleted or transferred to another location.

The virus also establishes a permanent connection to a remote server, which allows attackers to execute various commands on the victim's device, including requesting certain data, setting additional tracking parameters, and downloading additional malicious software. FireScam is able to track changes in activity on the device's screen, recording various events lasting more than 1000 ms. The virus carefully monitors all transactions, trying to intercept the victim's confidential payment data. Everything that the user types and copies to the clipboard is classified and transmitted to a remote server.

While Cyfirma has no guesses as to who is the operator of the new malware, the company noted that the campaign is a «sophisticated and multi-layered threat» that «uses advanced masking techniques». The company's specialists recommend that users be cautious about files they download from potentially unreliable sources.

Natasha Kumar

Natasha Kumar has been a reporter on the news desk since 2018. Before that she wrote about young adolescence and family dynamics for Styles and was the legal affairs correspondent for the Metro desk. Before joining The Times Hub, Natasha Kumar worked as a staff writer at the Village Voice and a freelancer for Newsday, The Wall Street Journal, GQ and Mirabella. To get in touch, contact me through my natasha@thetimeshub.in 1-800-268-7116

Share
Published by
Natasha Kumar

Recent Posts

The pseudo -agrarian scam: In Berdichev, police are investigating fraud for 240 thousand hryvnias

< img src = "/uploads/blogs/a9/ff/ib-FQ415k6n2_3b8135ed.jpg" Alt = "Affau from Pseudo-Agrarians: In Berdichev police investigate fraud…

2 hours ago

TikTok social network will allow users from the US to download the application from the site

< IMG SRC = "/Uploads/Blogs/92/CA/IB-FQ3SLTET1_240DF4A4.jpg" Alt = "Tiktok will allow users from the US to…

2 hours ago

Ilon Musk will create 10,000 robots Optimus Humanoids in 2025

< img src = "/uploads/blogs/44/4a/ib-fq3t1hmau_4A499ea2.jpg" Alt = "Ilon Musk will create 10,000 robots of humanoid…

4 hours ago

Another underwater cable is damaged in the Baltic Sea – this time Russian

< img src = "/uploads/blogs/04/26/ib -FQ464s1q5_c5b8557e.jpg" Alt = "in the Baltic Sea is damaged another…

4 hours ago

8 out of 10 men are ready to have a relationship with a cyber fever instead of a real woman – The Mirror

< img src = "/uploads/blogs/00/7e/ib-FQ417f7_ef7b2715.jpg" Alt = "8 of 10 men are ready to have…

4 hours ago

Ukrainians write about crashes in “Action”: what answered in the Ministerfra

< img src = "/uploads/blogs/eb/84/ib-FQ45Tcrnb_f7b27152.jpg" Alt = "Ukrainians write about failures in & quot; <…

4 hours ago