ESET Research discovers EvilVideo: Telegram app for Android targeted by zero-day exploit sending malicious videos

ESET researchers discovered a zero-day exploit, which targets the Telegram app for Android, that appeared for sale for an unspecified price in an underground forum post from June 2024. Using the exploit to abuse a vulnerability that ESET named “EvilVideo,” attackers could share malicious Android payloads via Telegram channels, groups, and chats, and make them … More ESET Research discovers EvilVideo: Telegram app for Android targeted by zero-day exploit sending malicious videos

ESET Research: Hamster Kombat game misused by cybercriminals as spyware and infostealer

ESET researchers have discovered threats abusing the success of the Hamster Kombat clicker game. In the past few months, the Telegram clicker game Hamster Kombat has taken the world of cryptocurrency game enthusiasts by storm. As was to be expected, the success of Hamster Kombat has also brought out cybercriminals, who have already started to … More ESET Research: Hamster Kombat game misused by cybercriminals as spyware and infostealer

ESET Research: Arid Viper group targets Middle East, poisons Palestinian app with spyware

ESET researchers have identified five campaigns that employ trojanised apps to target Android users. Most likely carried out by the Arid Viper APT group, these campaigns started in 2022, and three of them are still ongoing at the time of publication of this press release. They deploy multistage Android spyware, which ESET has named AridSpy, … More ESET Research: Arid Viper group targets Middle East, poisons Palestinian app with spyware

ESET discovers targeted attack via fake messaging apps, available on web and Google Play

ESET researchers have discovered an active espionage campaign named eXotic Visit, targeting Android users with apps primarily posing as messaging services. While these apps offer functional services as bait, they are bundled with the open-source XploitSPY malware. ESET has named this campaign eXotic Visit and has tracked its activities from November 2021 through to the … More ESET discovers targeted attack via fake messaging apps, available on web and Google Play