Baohuo Malware Exploits Telegram X on Android Devices

26 Oct 2025

Hackers have weaponized Telegram X on Android, deploying the Android.Backdoor.Baohuo.1.origin malware that puts user devices at risk across Brazil and Indonesia since mid-2024. Originally inserted into versions of Telegram X, the backdoor lets attackers seize control over user accounts.

Malware Distribution and Targets

The malicious software, Baohuo, spreads through deceptive in-app ads and third-party store downloads. Users in Brazil and Indonesia receive Portuguese and Indonesian language-targeted versions. The affected devices, over 58,000 in number, include a wide range of Android smartphones, tablets, TV boxes, and vehicle systems spread across approximately 3,000 models.

Technical Mechanisms and Risks

Baohuo uses advanced tactics to remain hidden while enabling unauthorized access and data theft. It employs mirrored Telegram methods and the Xposed framework to disguise its activity. Through these, attackers can intercept clipboard data and manipulate app behavior, including inflating channel subscriber counts, while avoiding detection.

Command and Control Operations

Utilizing Redis channels for its command-and-control infrastructure alongside traditional servers, Baohuo coordinates its operations. Device information and user data, including authentication tokens and message histories, are extracted every three minutes, posing a significant threat to privacy and security.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6235147
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1208759
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
469716
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
451048
downloads

News and reviews for Mobile Android

Baohuo Malware Exploits Telegram X on Android Devices

Baohuo malware compromises Telegram X users, particularly in Brazil and Indonesia, risking full device control since mid-2024.

Read more

Enhance Android Customization with Top Widget and Icon Apps

Improve device experience with popular Android customization apps for widgets, icons, and wallpapers.

Read more

Instagram Adds Watch History Feature for Reels

Instagram's new Watch History feature for Reels aids users in revisiting past videos.

Read more

Rollout of Google Home 4.1 Update Expands Features

Google Home 4.1 update expands Ask Home, enhances scrolling on iOS, and fixes lighting controls. Available in multiple countries now.

Read more

GameHub v5.2 Enhances Steam and Emulation Features

GameHub v5.2 update brings new Steam functionalities and emulation improvements for Android users.

Read more

Android Deals Feature Discounted Games and Apps

Today's top Android deals include Subnautica and Wind Peaks, with various discounts on games and apps.

Read more

Kik User in Louisville Faces Child Pornography Charges

A Louisville man allegedly used Kik for child pornography distribution, raising concerns about user anonymity and safety on the app.

Read more

Google's EyeDropper App Set for Android 17 Release

Google's EyeDropper app introduces a new color picker API for Android 17, enhancing app integration.

Read more

YouTube Rolls Out Mobile Redesign with New Icons

YouTube's mobile apps for Android and iOS receive a redesign with bolder icons and UI tweaks, affecting thousands of users.

Read more

YouTube Unveils Major Video Player Redesign on Mobile

YouTube's largest video player update enhances UI on Android, iOS with bolder controls and cleaner layout.

Read more