Attention! Malware-containing apps identified on Google Play Store and Galaxy Store
Aplicativos falsos do Signal e Telegram utilizaram o malware BadBazaar para espionar celulares; o Brasil está na lista de países atingidos
Malicious apps used for espionage activities have been detected on both the Google Play Store and the Samsung Galaxy Store. Brazil is among the locations affected by this threat.
The Signal Plus Messenger and FlyGram apps represent malicious variants of the well-known Signal and Telegram messaging platforms, and carry with them the spyware called BadBazaar.
According to ESET, a cybersecurity firm that identified the threat, apps associated with the Chinese hacking group APT GREF exploited the open-source nature of the Signal and Telegram platforms. They re-created the apps, deliberately incorporating malicious spying code.
Brazil is on the list
In addition to Brazil, other countries have been affected: Denmark, Democratic Republic of Congo, Germany, Hong Kong, Hungary, Lithuania, Netherlands, Poland, Portugal, Singapore, Spain, Ukraine, United States and Yemen.
According to Bleeping Computer, the FlyGram app has been available on the Google Play Store since July 2020, before being removed in January 2021. During that time, it has racked up around 5.000 installs. As of this writing, the app remains available on the Samsung Galaxy Store.
In July 2022, the Signal Plus Messenger app was made available on the Google and Samsung stores. However, Google chose to remove it in May. Meanwhile, on the Galaxy Store, the app remains available for download.
How do malicious apps work?
Experts explain that the purpose behind these applications is to obtain users' personal data. In the example of FlyGram, the ability to collect information such as the contact list, call history and data from the user's Telegram account was found.
When users activated Telegram's data backup and restore function, a remote server under the control of malicious actors was able to acquire information about the social media platform's activity.
According to ESET’s assessment, approximately 13.953 FlyGram accounts have activated the data backup and restore option. However, the total number of users of the compromised version of Telegram has not been publicly disclosed.
The malicious version of Signal, in turn, collected similar information, but its main purpose was to spy on communications conducted through the messaging platform. This included extracting the PIN codes used to safeguard Signal accounts.