ESET Finds Zero-Day Exploit "EvilVideo" Targeting Telegram on Android

Apps & Games / Mobile / Android / ESET Finds Zero-Day Exploit "EvilVideo" Targeting Telegram on Android
01 Aug 2024

In a recent development that underscores the ongoing battle between cybersecurity and malicious actors, researchers have unveiled a zero-day exploit targeting the Telegram messaging app on Android devices. This vulnerability, identified by the Slovakia-based cybersecurity firm ESET and dubbed “EvilVideo,” could have enabled attackers to send harmful payloads masquerading as legitimate multimedia files.

Details of the Exploit

The exploit was discovered on an underground forum in early June, where it was being sold by a user known as “Ancryno.” The seller showcased the exploit through screenshots and a video demonstrating its functionality within a public Telegram channel. This exploit leveraged Telegram’s default setting, which automatically downloads media files, allowing attackers to send malicious payloads through channels, groups, and chats.

While users could manually disable the automatic download feature, the risk remained if they inadvertently tapped the download button for a shared file. Upon attempting to play what appeared to be a video, users would receive a message indicating that the file could not be played, with a suggestion to use an external player. This is where the malicious intent lay; hackers had disguised a harmful application as this external player.

Fortunately, Telegram addressed this vulnerability in versions 10.14.5 and above, released earlier this month. In the updated version, any malicious file shared in a chat is now accurately displayed as an application, rather than a video, thereby mitigating the risk of inadvertent installation.

Potential Impact and Unknowns

Despite the patch, the exploit had a window of approximately five weeks during which it could have been exploited. However, ESET has not confirmed whether it was actively used in the wild. The identity of the hacker group or individual behind this exploit remains unclear, as does their intended use for it and its overall effectiveness.

Adding another layer of intrigue, the same underground forum account that advertised the EvilVideo exploit has also promoted Android cryptomining-as-a-service malware, claiming it to be fully undetectable. This raises further questions about the capabilities and intentions of those operating in the shadows of the digital landscape.

Does Telegram app work in UK?

Yes, the Telegram app works in the UK. It is available for download on various platforms, including iOS, Android, and desktop computers. Users in the UK can access all of Telegram's features, such as messaging, group chats, channels, and more, provided they have an active internet connection.

How to get a free phone number for Telegram?

To get a free phone number for Telegram, you can use services like Google Voice (available in the U.S.), TextNow, or other similar online services that offer temporary or virtual phone numbers. Sign up for one of these services, obtain a phone number, and use it to register your Telegram account. Note that some services may have limitations based on your location.
Update: 01 Aug 2024

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4460136
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
731337
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
382311
downloads
Grand Theft Auto V

Grand Theft Auto V

Latest update Grand Theft Auto V download for free for Windows PC or Android mobile

4
962 reviews
218576
downloads

News and reviews for Mobile Android

Swiggy Enhances App with User-Friendly Offline Features

Swiggy Enhances App with User-Friendly Offline Features

Swiggy's Android app now includes offline features for enhanced user convenience. The app allows users to access saved addresses, view past orders, and manage notifications without an internet connection, streamlining the food ordering process.

YouTube Enhances Global Communication with Comment Translation

YouTube Enhances Global Communication with Comment Translation

YouTube offers seamless comment translation on Android, bridging language barriers and fostering global interaction.

Leading FPS Games Making Waves on Android in 2025

Leading FPS Games Making Waves on Android in 2025

Explore top FPS titles on Android, from immersive multiplayer worlds to thrilling survival experiences. Discover Modern Combat 5 and Call of Duty: Warzone Mobile's captivating action.

New Malware Campaign Targets Indian Messaging Apps

New Malware Campaign Targets Indian Messaging Apps

Indian agencies detect 'Dance of the Hillary' malware aimed at Indian users through messaging apps, risking data theft and unauthorized access.

Google's Android Gallery App Offers Unseen Simplicity

Google's Android Gallery App Offers Unseen Simplicity

Google's Gallery app, designed for offline photo viewing, remains understated despite over a billion downloads and six years in existence.

Android Update Enhances App Performance with New Requirements

Android Update Enhances App Performance with New Requirements

Starting November 2025, Android apps must support a 16 KB page size for better performance. Google aims to improve memory management and app efficiency.

Inked Featured in Google Play's Latest App Deals for Android

Inked Featured in Google Play's Latest App Deals for Android

Explore Google's promotional deals including Inked, available on Android. Samsung opens reservations for new device at best price this year. Inked offers a unique storyline of love and hope as a samurai's quest unfolds.

WhatsApp Updates Warning on Unofficial Apps and iOS Compatibility

WhatsApp Updates Warning on Unofficial Apps and iOS Compatibility

WhatsApp urges users to update iOS and avoid unofficial apps to ensure privacy and security. Old iPhone users risk service loss and permanent bans.

Informed Delivery Expands with New USPS Android App

Informed Delivery Expands with New USPS Android App

USPS is testing an Android app to enhance Informed Delivery, letting users track mail and packages, view images, and receive updates on their smartphones.

Google Enforces Major Crackdown on Harmful Android Apps

Google Enforces Major Crackdown on Harmful Android Apps

Google blocks 2.3 million dangerous apps, enhancing security for Android. Emphasizes using Play Protect to shield against malware and fraud. More than 158,000 bad accounts barred, scanning 200 billion apps daily.

All article