"Google Play Infected: Trojanized Signal and Telegram Apps Spread Chinese Android Spyware"

1 min read
Source: Ars Technica
"Google Play Infected: Trojanized Signal and Telegram Apps Spread Chinese Android Spyware"
Photo: Ars Technica
TL;DR Summary

Researchers have discovered fake apps on Google Play that impersonated the popular messaging platforms Signal and Telegram. These malicious apps, named Signal Plus Messenger and FlyGram, were able to extract sensitive information from legitimate accounts when users performed certain actions. The apps were built on open source code from Signal and Telegram and contained an espionage tool called BadBazaar, which has been linked to a China-aligned hacking group. Signal Plus Messenger was able to spy on Signal messages by secretly linking the compromised device to the attacker's Signal device. Google has removed the apps from Play, but they remain available in the Samsung store. Users are advised to download only official versions of messaging apps from official channels to avoid falling victim to fake apps.

Share this article

Reading Insights

Total Reads

0

Unique Readers

21

Time Saved

3 min

vs 5 min read

Condensed

85%

823125 words

Want the full story? Read the original article

Read on Ars Technica