Signal Private Messenger app download page on the Google Play Store.
© Ascannio/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Researchers have discovered trojanized Android apps mimicking Signal and Telegram on the Google Play Store and Samsung Galaxy Store. These spyware apps have been downloaded by thousands of unsuspecting users in the United States, the European Union (EU), and other parts of the world, cybersecurity company ESET said.

In a report on Wednesday, August 30, ESET researchers said these malicious apps — Signal Plus Messenger and Flygram — give the threat actor access to a target’s Signal and Telegram messages and core functions on Android devices.

The fake apps were created by “patching the open-source Signal and Telegram apps for Android with malicious code.” The same developer created both apps. Ironically, many users turn to Signal and Telegram as they’re more privacy-friendly.

ESET researchers suspect the “China-aligned APT group GREF” is behind this campaign, as the group has used the same malicious Badbazaar code in the apps in other campaigns.

Google has since removed these phony Signal and Telegram apps from the Play Store, but they’re still on the Samsung Galaxy Store.

Signal Plus Messenger and FlyGram Apps

When a victim installs the Signal Plus Messenger app, the malware activates several espionage features.

“Signal Plus Messenger can spy on Signal messages by misusing the link device feature,” the report noted. This allows hackers to listen to individuals via their device’s microphone, snap pictures through the camera, steal data like SMS messages and location information, and more.

ESET research: Android users targeted by trojanized Signal and Telegram apps.

“During this communication, the app sends the [hacker] server various device information, such as IMEI number, phone number, MAC address, operator details, location data, Wi-Fi information, Signal PIN number that protects the account (if enabled by the user), emails for Google accounts, and contact list,” the report explained.

An IMEI number is a unique hardware serial number for each device, while a MAC address can reveal an individual’s physical location. Combined with Wi-Fi data, location data, and even Signal PINs, hackers can obtain an astonishingly detailed profile of an individual.

The IMEI number may allow the hacker to track, disable, or manipulate a specific device remotely. MAC addresses and Wi-Fi information can provide a granular view of users’ physical movements and habits, down to which networks they connect to and when.

ForFlyGram, the Telegram impersonator, the functionalities are similarly invasive. “FlyGram can access Telegram backups if the user enabled a specific feature added by the attackers; the feature was activated by at least 13,953 user accounts,” the report said.

It appears that the China-linked espionage campaign is targeting specific groups. This may include “human rights activists, journalists, and academics.”

“Uyghurs and other Turkic ethnic minorities” were previously targeted by BadBazaar malware, the report said.

“FlyGram malware was also seen shared in a Uyghur Telegram group, which aligns with previous targeting of the BadBazaar malware family,” the researchers noted.

How to Protect Your Device From Spyware

ESET researchers described Signal Plus Messenger’s spying technique as unique, explaining that this “is the first documented case of spying on a victim’s Signal communications,” the report said.

The Android ecosystem is a top target for cybercriminals. In August, a Google Threat Horizons report revealed how hackers bypass Play Store security checks.

“The only way to prevent becoming a victim of a fake Signal – or any other malicious messaging app – is to download only official versions of such apps, only from official channels,” the report warned.

We recommend following ESET’s advice closely and keeping your apps up-to-date. Also, consider using a trusted antivirus software to block malicious apps from compromising your device.

If you believe you’ve installed one of these malicious apps, consult our Android malware removal guide for instructions on how to wipe it from your device.

For more cybersecurity news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment