New FireScam Android data-theft malware poses as Telegram Premium app

Teilen:

A new Android malware named ‘FireScam’ is being distributed as a premium version of the Telegram app via phishing websites on GitHub that mimick the RuStore, Russia’s app market for mobile devices.

RuStore launched in May 2022 by the Russian internet group VK (VKontakte) as an alternative to Google Play and Apple’s App Store, following Western sanctions that impacted Russian users’ access to mobile software.

It hosts apps that are compliant with Russian regulations and it was created with the support of the Russian Ministry of Digital Development.

According to researchers at threat management company Cyfirma, the malicious GitHub page mimicking RuStore first delivers a dropper module called GetAppsRu.apk.

The dropper APK is obfuscated using DexGuard to evade detection and acquires permissions that allow it to identify installed apps, gives it access to the device’s storage, and install additional packages.

Next, it extracts and installs the main malware payload, ‘Telegram Premium.apk’, which requests permissions to monitor notifications, clipboard data, SMS, and telephony services, among others.

RuStore clone hosted on a GitHub.io domain
RuStore clone hosted on a GitHub.io domain
Source: CYFIRMA

FireScam capabilities

Upon execution, a deceptive WebView screen showing a Telegram login page steals the user’s credentials for the messaging service.

FireScam establishes communication with a Firebase Realtime Database where it uploads stolen data in real-time and registers the compromised device with unique identifiers, for tracking purposes.

Cyfirma reports that stolen data is only stored in the database temporarily and then wiped, presumably after the threat actors filtered it for valuable information and copied it to a different location.

The malware also opens a persistent WebSocket connection with the Firebase C2 endpoint for real-time command execution like requesting specific data, triggering immediate uploads to the Firebase database, downloading and executing additional payloads, or adjusting the surveillance parameters.

FireScam can also monitor changes in the screen activity, capturing on/off events and log the active app at the time as well as activity data for events lasting for more than 1,000 milliseconds.

The malware also meticulously monitors any e-commerce transactions, attempting to capture sensitive financial data.

Anything the user types, drags and drops, copies to clipboard, and intercepts even data automatically filled from password managers or exchanges between apps, categorized, and exfiltrated to the threat actors.

Data exfiltrated by FireScam
Data exfiltrated by FireScam
Source: CYFIRMA

Although Cyfirma does not have any hints pointing to FireScam’s operators, the researchers say that the malware is a “sophisticated and multifaceted threat” that “employs advanced evasion techniques.”

The company recommends users to execute caution when opening files from potentially untrusted sources or when clicking on unfamiliar links.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:11 am, Juni 9, 2025
Wetter-Symbol 16°C
L: 15° | H: 17°
broken clouds
Luftfeuchtigkeit: 73 %
Druck: 1021 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 76%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0.2 mm 20% 9 mph 75 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 20°°C 0.8 mm 80% 11 mph 83 % 1020 mb 0 mm/h
Mi. Juni 11 10:00 pm
Wetter-Symbol
13° | 23°°C 0.2 mm 20% 12 mph 81 % 1021 mb 0 mm/h
Do. Juni 12 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 10 mph 81 % 1018 mb 0 mm/h
Fr. Juni 13 10:00 pm
Wetter-Symbol
16° | 27°°C 1 mm 100% 11 mph 93 % 1020 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 73 % 1022 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 18°°C 0.2 mm 20% 8 mph 67 % 1022 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 8 mph 60 % 1021 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 8 mph 61 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 75 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 9 mph 81 % 1018 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 11 mph 83 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 10 mph 83 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,587.08
0.14%
Ethereum(ETH)
€2,184.25
-0.92%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.95
0.98%
Solana(SOL)
€132.12
0.73%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.159083
-1.00%
Shiba Inu(SHIB)
€0.000011
-1.37%
Pepe(PEPE)
€0.000011
0.28%
Peanut das Eichhörnchen(PNUT)
€0.233175
1.70%
Nach oben scrollen