Photo Depicting Telegram on Play Store in Trouser Pocket
© Iljanaresvara Studio/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Google has removed several doppelganger Telegram apps from the Play Store. These apps were designed to steal sensitive personal information, including contacts, messages, and files, from compromised accounts, according to Kaspersky.

In a report on Sept. 8, Kaspersky said the vendors of the modified Telegram apps claimed they had the “fastest apps” compared to the official Telegram app.

While these malicious apps have the same interface and basic functionality as Telegram, they also contain code that allows them to harvest users’ personal information.

The description of these apps was in “traditional Chinese, simplified Chinese and Uighur,” indicating that the spyware campaign targeted people in particular regions of China.

Data-Harvesting Malware in Fake Telegram Apps

Kaspersky researchers found that the fake Telegram apps have malicious code that allows them to collect users’ names, contacts, phone numbers, incoming messages, and the files received/sent by the user. All this data is sent to a server controlled by the hacker. It also records other data like a sender’s name and ID as well as the names and IDs of channels.

The malware persists even when targets change their names on Telegram or the number linked to their Telegram account.

Many may not question the safety of apps on the Google Play Store. “What can possibly be wrong with a Telegram mod duly tested by Google Play and available through the official store?” Kaspersky’s report said.

It’s unclear how these apps passed the security checks to get on Google Play, but threat actors are known to use various dubious means to bypass Play Store security checks. In August, Google revealed how malicious apps bypass Play Store security using a technique known as “versioning.”

“Google Play’s safety checks are robust, but determined malicious actors sometimes find ways to bypass them. Fake apps often employ tactics like obfuscation and deceptive descriptions to slip past Google Play’s checks. Fraudsters also use sophisticated techniques to mask their true intentions. Some apps even initially function as legitimate apps before activating malicious behavior, making detection more challenging,” Igor Golovin, a security expert at Kaspersky, told VPNOverview.

How to Avoid Malicious Apps

Sticking to an official app store like Google Play is not enough to avoid malicious apps. We recommend researching the developer of each app you want to download and ensure they’re trustworthy.

“As you can see, being an official store item does not guarantee an app’s security, so be wary of third-party messenger mods, even those distributed by Google Play,” Kaspersky said.

We also recommend using an antivirus solution with real-time protection to block malicious apps before they compromise your device. Check out our guide to the best antivirus software of 2023 for some suggestions.

For more insights about dangerous apps, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment