ESET Finds Zero-Day Exploit "EvilVideo" Targeting Telegram on Android

01 Aug 2024

In a recent development that underscores the ongoing battle between cybersecurity and malicious actors, researchers have unveiled a zero-day exploit targeting the Telegram messaging app on Android devices. This vulnerability, identified by the Slovakia-based cybersecurity firm ESET and dubbed “EvilVideo,” could have enabled attackers to send harmful payloads masquerading as legitimate multimedia files.

Details of the Exploit

The exploit was discovered on an underground forum in early June, where it was being sold by a user known as “Ancryno.” The seller showcased the exploit through screenshots and a video demonstrating its functionality within a public Telegram channel. This exploit leveraged Telegram’s default setting, which automatically downloads media files, allowing attackers to send malicious payloads through channels, groups, and chats.

While users could manually disable the automatic download feature, the risk remained if they inadvertently tapped the download button for a shared file. Upon attempting to play what appeared to be a video, users would receive a message indicating that the file could not be played, with a suggestion to use an external player. This is where the malicious intent lay; hackers had disguised a harmful application as this external player.

Fortunately, Telegram addressed this vulnerability in versions 10.14.5 and above, released earlier this month. In the updated version, any malicious file shared in a chat is now accurately displayed as an application, rather than a video, thereby mitigating the risk of inadvertent installation.

Potential Impact and Unknowns

Despite the patch, the exploit had a window of approximately five weeks during which it could have been exploited. However, ESET has not confirmed whether it was actively used in the wild. The identity of the hacker group or individual behind this exploit remains unclear, as does their intended use for it and its overall effectiveness.

Adding another layer of intrigue, the same underground forum account that advertised the EvilVideo exploit has also promoted Android cryptomining-as-a-service malware, claiming it to be fully undetectable. This raises further questions about the capabilities and intentions of those operating in the shadows of the digital landscape.

Does Telegram app work in UK?

Yes, the Telegram app works in the UK. It is available for download on various platforms, including iOS, Android, and desktop computers. Users in the UK can access all of Telegram's features, such as messaging, group chats, channels, and more, provided they have an active internet connection.

How to get a free phone number for Telegram?

To get a free phone number for Telegram, you can use services like Google Voice (available in the U.S.), TextNow, or other similar online services that offer temporary or virtual phone numbers. Sign up for one of these services, obtain a phone number, and use it to register your Telegram account. Note that some services may have limitations based on your location.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7002809
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1534167
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
650241
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
477301
downloads

News and reviews for Mobile Android

Android 16 QPR3 Update Fixes App Crashes on Pixel

Google releases Android 16 QPR3 Beta 1.1, remedying app crashes on Pixel. Impacted apps include Teams, OneDrive, banking. Pixel users advised to update.

Read more

QPR3 Update Fixes App Crashes on Pixel Devices

Android 16 QPR3 Beta 1.1 resolves app crash issues on Pixel devices in the beta program.

Read more

Revamp Adds Floating Bar to Gemini on Android

Google updates Gemini with a floating bar for Android, enhancing usability and interface. Gemini Labs to test features.

Read more

Google Adds App Lock to Android Automotive

Google introduces App Lock for Android Automotive, enabling PIN protection for individual apps to enhance privacy within shared vehicles.

Read more

Android Automotive Boosts Privacy with New App Lock Feature

Google adds App Lock to Android Automotive, enhancing in-car privacy via PINs.

Read more

Android Auto Version 15.9 Hints at Google Cast Integration

Android Auto 15.9 suggests Google Cast integration, enabling media casting from smartphones to car displays, bolstering in-car streaming capabilities.

Read more

Google Settles Play Store Lawsuit for $630 Million

Google agrees to a $630 million settlement over Play Store practices for purchases from 2016 to 2023 in a U.S. class-action case.

Read more

Holiday Android Deals Include Greak and 2112TD Discounts

Explore Android deals with discounts on Greak, 2112TD, and more apps, boosting savings for users.

Read more

Holiday Android Apps and Games Discounted in 2025 Sale

Holiday sales on Android apps and games for 2025 include big discounts on popular titles like Kahuna and EXIT – Trial of the Griffin.

Read more

Discover Five Underrated Google Apps for Android

Explore five underrated Google apps that enhance learning, productivity, and accessibility.

Read more