Telegram App Flaw Exploited to Spread Malware Hidden in Videos

July 24, 2024 at 09:19AM A zero-day security flaw in Telegram’s Android app called EvilVideo allowed attackers to share malicious files camouflaged as videos. The exploit appeared for sale in June 2024 and was addressed by Telegram in July’s version 10.14.5. Additionally, cybercriminals are leveraging the popularity of the Telegram-based game Hamster Kombat for monetary … Read more

Attackers Exploit ‘EvilVideo’ Telegram Zero-Day to Hide Malware

July 23, 2024 at 12:29PM Telegram has addressed a zero-day flaw in older Android app versions, allowing attackers to hide malicious payloads in video files. ESET researchers discovered the flaw, “EvilVideo”, on a hacker forum. Exploit affected versions 10.14.4 and below. Updates to version 10.14.5 and above fix the issue. Users should update immediately to … Read more

Telegram zero-day allowed sending malicious Android APKs as videos

July 22, 2024 at 10:47AM Summary: The “EvilVideo” zero-day vulnerability in Telegram for Android allowed threat actors to send malicious APK payloads disguised as video files. ESET researchers discovered the flaw and notified Telegram, which released a patch in version 10.14.5. The exploit required multiple steps for execution, reducing the risk of successful attacks. Users … Read more