/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A Telegram for Android zero-day, patched on July 11, let attackers send malicious Android APK payloads as video files; the exploit was for sale from June 6

Bill Toulas / BleepingComputer :

BleepingComputer Bill Toulas

Context & Ripple Effects

This is another Android attack path centered on trusted app workflows rather than a device-wide flaw. Related coverage has previously documented an unpatched remote-code-execution issue in a widely used Android file-sharing app, showing how app-level vulnerabilities can become high-value delivery routes.

The case also fits a broader abuse of messaging infrastructure: subsequent related coverage describes Telegram bots used to distribute Android-targeting malware at international scale. Here, the key differentiator is the ability to make an installable payload appear to be ordinary video content.

First-order effects

  • Telegram for Android users exposed before the July 11 patch could receive malicious APKs disguised as video files, weakening the visual cues users rely on to judge attachments.
  • The vulnerability's sale beginning June 6 gave buyers a ready-made Android malware-delivery mechanism until Telegram patched it.

Second-order effects

  • Malware operators can pair deceptive file presentation with existing Android APK lures, increasing pressure on messaging platforms to harden attachment parsing and file-type validation.
  • The episode reinforces why Android security teams must treat third-party app update adoption as part of endpoint risk, alongside platform patches; earlier coverage has tracked Android flaws being turned into drive-by and malvertising attacks.

Third-order effects

  • If attackers continue to monetize flaws that cross the boundary between a displayed attachment and executable software, messaging apps will increasingly be judged as security-critical distribution surfaces, not merely communications clients.
  • The pattern favors faster disclosure-to-patch cycles and stronger safeguards around executable content, though the corpus does not establish whether this exploit saw broad use before remediation.

The trend: Android malware delivery is shifting toward trusted communication and sharing channels, where deceptive content presentation can lower users' defenses before platform-level protections intervene.

Discussion

  • @lukasstefanko Lukas Stefanko on x
    @ESETresearch @ESET The exploit rely on the threat actor being able to create a payload that displays an Android app as a video and not as a binary attachment. Once shared in chat, the malicious payload appears as a 30-second video [image]
  • @lukasstefanko Lukas Stefanko on x
    Exploiting the #EvilVideo vulnerability on Telegram We discovered a 0-day Telegram for Android exploit that allows sending malicious apps disguised as videos https://www.welivesecurity.com/ ... @ESETresearch @ESET [video]
  • @lukasstefanko Lukas Stefanko on x
    @ESETresearch @ESET We found the EvilVideo exploit being advertised for sale on an underground forum since Jun 6, 2024. Price wasn't included. [image]
  • @lukasstefanko Lukas Stefanko on x
    @ESETresearch @ESET If user tries to play the “video”, Telegram displays a message that it is unable to play it and suggests using an external player. If the user taps the Open button, payload will request to install a malicious app disguised as the external player. [image]