The malware distributes a working but trojanized version of the Telegram app by pretending to be the mobile app of an instant chat site
ESET, a global leader in the cybersecurity market, has identified an active campaign by the APT StrongPity group that exploits a fully functional but Trojan-containing version of the Telegram app, passing it off as an app from the Shagle site (a casual video chat platform, accessible only via browser), which in reality does not exist. The backdoor has several spying functions: 11 dynamically activated modules are responsible for recording phone calls, collecting SMS messages, collecting lists of call logs and contact lists, and much more. These modules were officially documented for the first time. If the victim grants the StrongPity malicious app access to notifications and accessibility services, the app will also have access to incoming notifications from 17 apps including Viber, Skype, Gmail, Messenger, and Tinder, and will be able to exfiltrate chat communications from other apps. The campaign is likely limited, as ESET's telemetry has not yet identified any victims.
Unlike the authentic Shagle site which does not provide an official mobile app to access its services, the fake site only provides an Android app to download, without the possibility of streaming via the web. This trojan-affected app was never made available on the Google Play Store.
The malicious code, its features, category names, and the certificate used to sign the APK file are identical to those of the previous campaign; ESET therefore considers this operation to belong to the StrongPity group. Code analysis revealed that the backdoor is modular and that additional binary modules are downloaded from the C&C server. This means that the number and type of modules used can be changed at any time to suit the demands of the campaign, if managed by the StrongPity group.
"During our investigation, the analyzed version of the malware available on the emulator's website was no longer active and it was no longer possible to successfully install and activate the backdoor functionality. This is because StrongPity did not obtain the API ID for the malicious Telegram app. But this could change at any time if the threat actor decides to update it," he says Lukáš Štefanko, ESET researcher who analyzed the app.
The modified version of the Telegram app uses the same ID as the original. Package names must be unique IDs for each Android app and must be unique on each device. This means that it will not be installed if the official version is already present on the device. “This could mean either that the threat actor communicates with potential victims first and pushes them to uninstall Telegram from their devices if it is installed, or that the campaign focuses on countries where the use of Telegram is still not widespread,” adds Štefanko.
The StrongPity app should have worked just like the official version of Telegram, using standard APIs well documented on the official website, but today it is no longer active. Compared to the first StrongPity malware discovered for mobile devices, this backdoor has extended spying features, as it is capable of spying on incoming notifications and exfiltrating chat communications, if the victim activates accessibility services.
For more technical information on the latest StrongPity app, check out the blog post “StrongPity espionage campaign targeting Android users” su WeLiveSecurity.






