By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Telegram zero-day allowed sending malicious Android APKs as videos
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Telegram zero-day allowed sending malicious Android APKs as videos
Tech News

Telegram zero-day allowed sending malicious Android APKs as videos

By admin 4 Min Read
Share
SHARE

A Telegram for Android zero-day vulnerability dubbed ‘EvilVideo’ allowed attackers to send malicious Android APK payloads disguised as video files.

A threat actor named ‘Ancryno’ first began selling the Telegram zero-day exploit on June 6, 2024, in a post on the Russian-speaking XSS hacking forum, stating the flaw existed in Telegram v10.14.4 and older.

ESET researchers discovered the flaw after a PoC demonstration was shared on a public Telegram channel, allowing them to obtain the malicious payload.

Threat actor selling the exploit on a hacking forum
<strong>Threat actor selling the exploit on a hacking forum</strong><br /><em>Source: ESET</em>

ESET confirmed the exploit worked in Telegram v10.14.4 and older and named it ‘EvilVideo.’ ESET researcher Lukas Stefanko responsibly disclosed the flaw to Telegram on June 26 and again on July 4, 2024.

Telegram responded on July 4, stating they were investigating the report and then patched the vulnerability in version 10.14.5, released on July 11, 2024.

This means the threat actors had at least five weeks to exploit the zero-day before it was patched.

While it is unclear if the flaw was actively exploited in attacks, ESET shared a command and control server (C2) used by the payloads at ‘infinityhackscharan.ddns[.]net.’

BleepingComputer found two malicious APK files using that C2 on VirusTotal [1, 2] that pretend to be Avast Antivirus or an ‘xHamster Premium Mod.’

Telegram zero-day exploit

The EvilVideo zero-day flaw only worked on Telegram for Android and allowed attackers to create specially crafted APK files that, when sent to other users on Telegram, appear as embedded videos.

ESET believes that the exploit uses the Telegram API to programmatically create a message that appears to show a 30-second video.

APK file previewed as a video on Telegram
<strong>APK file previewed as a 30-sec clip</strong><br /><em>Source: ESET</em>

On its default setting, the Telegram app on Android automatically downloads media files, so channel participants receive the payload on their device once they open the conversation.

For users who have disabled the auto-download, a single tap on the video preview is enough to initiate the file download.

When users attempt to play the fake video, Telegram suggests using an external player, which may cause recipients to tap the “Open” button and execute the payload.

Prompt to launch an external video player
<strong>Prompt to launch an external video player</strong><br /><em>Source: ESET</em>

Next, an additional step is required: the victim must enable the installation of unknown apps from the device settings, allowing the malicious APK file to install on the device.​

Final step adding friction in the exploit process
<strong>Step requiring the approval of APK installation</strong><br /><em>Source: ESET</em>

Though the threat actor claims the exploit is “one-click,” the fact that it requires multiple clicks, steps, and specific settings for a malicious payload to be executed on a victim’s device significantly reduces the risk of a successful attack.

ESET tested the exploit on Telegram’s web client and Telegram Desktop and found that it doesn’t work there because the payload is treated as an MP4 video file.

Telegram’s fix in version 10.14.5 now displays the APK file correctly in the preview, so recipients can no longer be deceived by what would appear as video files.

If you recently received video files that requested an external app to play via Telegram, perform a filesystem scan using a mobile security suite to locate and remove the payloads from your device.

Typically, Telegram video files are stored in ‘/storage/emulated/0/Telegram/Telegram Video/’ (internal storage) or in ‘/storage//Telegram/Telegram Video/’ (external storage).

ESET shared a video demonstrating the Telegram zero-day exploit, which can be watched below.


You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: 0-day, Android, APK, Mobile, Telegram, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Romance Hot Cyborgs And Dance To '90s Boy Bands In Warframe's Most Surprising Expansion Yet
Next Article What ‘Twisters’ Gets Right—and Wrong–about Tornado Science
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?