Cybersecurity experts from Cyfirma have discovered new Android malware named FireScam, which steals user data while pretending to be a Telegram Premium app. This was reported by the portal BleepingComputer.
How FireScam Spreads
FireScam is distributed through a GitHub page impersonating the Russian app store RuStore. Users are prompted to download a file named GetAppsRu.apk, which bypasses standard Android security measures thanks to built-in obfuscation mechanisms.
How the Virus Works
- Initial Download: After installation, FireScam requests access to device data, such as the list of installed apps and file storage.
- Main Malware: FireScam downloads and installs an app named Telegram_Premium.apk, which:
- Requests access to notifications, clipboard, and SMS content.
- Intercepts login credentials by displaying a fake Telegram login page.
- Sends stolen data to a Firebase Realtime Database server.
- Additional Capabilities: FireScam establishes a persistent connection to a remote server, allowing attackers to:
- Configure tracking settings.
- Download additional malicious files.
- Capture screen data, including payment details.
Dangers to Users
FireScam has extensive functionality for stealing personal information and enables attackers to control infected devices. This makes it especially dangerous for users who frequently make payments or enter confidential data on their smartphones.
How to Protect Yourself
- Only download apps from official stores like Google Play.
- Review app ratings and sources before installing.
- Install antivirus software and keep its database updated.
- Limit app permissions, especially if they request access unrelated to their primary functionality.
Android users are strongly advised to remain vigilant and avoid downloading suspicious apps to prevent falling victim to FireScam or similar threats.