Listen to this Post

A New Digital Trap Targets Telegram Users Worldwide
A dangerous Android malware operation has been exposed by PreCrime™ Labs, the threat intelligence arm of BforeAI. Over 600 malicious domains—many registered via the Gname registrar and written in Chinese—are part of an elaborate campaign to distribute fake Telegram APKs. The attack relies on deceptive branding, typosquatting tactics (like domains named “teleqram”), and SEO manipulation to trick users into downloading malware instead of the real messaging app. These fake APKs lead users into downloading from cloned sites like zifeiji.asia, which mimics Telegram’s visual identity so well that even tech-savvy users might fall for it.
The Anatomy of the Fake Telegram Campaign
This sophisticated malware campaign is built on an infrastructure of 607 fake domains that impersonate Telegram using nearly identical names such as “teleqram” and “telegramapp”. These sites lure users by promoting fake APKs through QR codes and aggressive SEO tactics to make them appear at the top of search results. The cloned domains direct users to a central site—zifeiji[.]asia—which mimics Telegram’s real download page, including its favicon, layout, and color scheme, further tricking users into believing the site is legitimate.
Victims unknowingly download Android packages sized between 60MB and 70MB, supposedly official Telegram apps. These files are signed using the outdated V1 signature scheme, exposing users with Android 5.0 to 8.0 to the infamous Janus vulnerability. This loophole allows cybercriminals to repackage apps with malware without changing the original signature, thus bypassing basic security checks.
Reverse engineering the infected APKs reveals they request high-risk permissions like READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE, enabling attackers to siphon off private user data. The use of insecure protocols such as HTTP and FTP leaves devices vulnerable to interception and manipulation.
What makes this even more insidious is the embedded MediaPlayer functions and socket-based callbacks in the code, which open up persistent backdoors for real-time surveillance, file theft, and command execution. There’s also a JavaScript file linked to telegramt.net that collects device fingerprints and browsing behavior, forwarding it to a suspicious domain, dszb77[.]com.
Even more alarming, the malware tries to communicate with an abandoned Firebase instance: tmessages2.firebaseio.com. Since Firebase names are not globally protected once abandoned, any attacker can hijack the instance by creating a project with the same name—keeping the malware operational indefinitely, even if the original group vanishes.
Security experts are now urging users to avoid downloading APKs from unofficial websites, especially blogs that imitate Telegram. These domains, using TLDs like .com, .top, .xyz, and .site, are engineered to spread rapidly across search engines and social media. With the malware allowing full remote command access and exfiltration of private data, the implications for Android device users are severe.
What Undercode Say:
The Deep Web of Deception and Exploitation
This campaign is not just another phishing attempt. It’s a meticulously crafted supply chain attack targeting Android’s most vulnerable layers. At its core lies a sophisticated exploitation of trust—leveraging visual design mimicry, search engine dominance, and outdated Android security flaws.
Janus Vulnerability Reawakened
The use of APKs signed only with the V1 scheme highlights a gaping security hole that many thought was already behind us. But millions of users still operate devices with Android versions 5.0 to 8.0, making this exploit frighteningly viable. This demonstrates how legacy vulnerabilities continue to be weaponized in modern attacks, especially in regions where outdated phones remain prevalent.
Weaponizing SEO and QR Codes
By exploiting SEO and QR codes, attackers have merged the worlds of social engineering and technical infiltration. A user scanning a QR code on what looks like a legitimate page is unlikely to suspect foul play. The Chinese-language site content, combined with references to the “Paper Plane Official Website,” adds another layer of confusion that enhances click-through rates and reduces user skepticism.
Firebase Hijacking: A Silent Killer
The Firebase misconfiguration is perhaps the most dangerous part. Firebase remains one of the most commonly integrated backend tools in Android apps, and few developers monitor inactive endpoints. A hijacked Firebase project linked to older apps can silently reactivate malicious infrastructure—no new APKs needed. This technique ensures persistence long after the original domain or server is taken down.
Cross-Device Data Harvesting
The malicious JavaScript hosted on telegramt.net isn’t limited to Android. It fingerprints platforms including iOS and desktop users, suggesting a multi-platform strategy. While Android is the main target, the infrastructure is clearly built for expansion into wider device ecosystems.
Indicators of a Larger Syndicate
The scale—607 domains with multiple TLDs—suggests automation, high funding, or both. It’s likely this campaign is backed by an organized cybercrime syndicate with state-level capabilities or at least access to a vast infrastructure network. The ongoing operation of the centralized hub (zifeiji.asia) and integration with modern analytics tactics signals a professional, evolving threat group.
Exploiting Telegram’s Popularity
Telegram is a prime target due to its popularity and frequent use in regions with limited digital literacy. Attackers are banking on users bypassing the Play Store to download APKs directly—a behavior common in countries where access to the Play Store is restricted or unreliable. These fake APKs capitalize on that exact weakness.
Defense Strategies for Enterprises and Individuals
Organizations should implement DNS filtering and monitor for typosquatted domains. End-users must be educated on the dangers of downloading APKs from non-official sources. Google and other platforms should enhance their algorithms to de-rank typosquatted and cloned domains, especially those masquerading as popular apps.
The Broader Implication: Android’s Open Nature
While Android’s openness is one of its strengths, it’s also its Achilles heel. The ability to sideload apps, combined with weak vetting by third-party stores, has created a fertile ground for cybercriminals. This incident underlines the urgent need for tighter app verification protocols across Android’s ecosystem.
🔍 Fact Checker Results:
✅ 607 fake domains confirmed by PreCrime™ Labs
✅ APKs exploit Janus vulnerability on Android 5.0–8.0
✅ Firebase hijacking risk fully validated by researchers
📊 Prediction:
📱 Android devices using outdated versions will remain high-risk targets
🎯 Cybercriminals will likely replicate this campaign for other popular apps
🛡️ Google will face pressure to flag typosquatted domains in SERPs and Chrome
References:
Reported By: cyberpress.org
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




