New Threat Research Identifies Malicious Telegram APK Campaign

BforeAI has revealed that its threat research division has identified a large malicious campaign of 607 domains linked to a large-scale phishing and malware campaign actively distributing application files claiming to be Telegram Messenger, registered through the Gname registrar, and are primarily hosted in the Chinese language. 

There were two instances in which applications were prompted for download, each being 60MB and 70MB in size, respectively. The new report provides the hash values gathered from this APK, depicts the blog-like appearance of a phishing site distributing the malicious Telegram APK, and shows the permissions requested by the malicious Telegram APK, flagged according to severity as well as proposed mitigations.

You can read the research here: https://bfore.ai/report/malicious-telegram-apk-campaign-advisory

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading