"Google Play Infected: Trojanized Signal and Telegram Apps Spread Chinese Android Spyware"

Researchers have discovered fake apps on Google Play that impersonated the popular messaging platforms Signal and Telegram. These malicious apps, named Signal Plus Messenger and FlyGram, were able to extract sensitive information from legitimate accounts when users performed certain actions. The apps were built on open source code from Signal and Telegram and contained an espionage tool called BadBazaar, which has been linked to a China-aligned hacking group. Signal Plus Messenger was able to spy on Signal messages by secretly linking the compromised device to the attacker's Signal device. Google has removed the apps from Play, but they remain available in the Samsung store. Users are advised to download only official versions of messaging apps from official channels to avoid falling victim to fake apps.
- Google removes fake Signal and Telegram apps hosted on Play Ars Technica
- Trojanized Signal and Telegram apps on Google Play delivered spyware BleepingComputer
- China-Linked BadBazaar Android Spyware Targeting Signal and Telegram Users The Hacker News
- This sneaky Android malware uses a rare technique to steal banking data TechRadar
- Chinese Group Spreads Android Spyware Via Trojan Signal, Telegram Apps DARKReading
Reading Insights
0
21
3 min
vs 5 min read
85%
823 → 125 words
Want the full story? Read the original article
Read on Ars Technica