Zimperium: a massive SMS stealer campaign has targeted Android devices worldwide using Telegram bots to infect devices in 113 countries since February 2022
A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware …
Context & Ripple Effects
Android malware has repeatedly scaled through seemingly legitimate or familiar distribution channels: prior research documented an Android operation affecting more than 10 million devices, while earlier Play Store apps abused SMS for premium charges. This campaign adds a bot-operated Telegram layer to that established mobile-fraud playbook.
The timing also follows disclosure of a Telegram-for-Android flaw used to disguise APKs as videos, underscoring how messaging environments can be abused for Android delivery or command workflows without implying Telegram itself is responsible for the malware.
First-order effects
- Affected Android users face theft of SMS content, putting text-delivered verification codes and account-recovery messages at risk.
- The operators gain a scalable control and infection mechanism through thousands of Telegram bots, while defenders must identify both malicious Android samples and their bot-linked infrastructure.
Second-order effects
- Services that still use SMS for authentication may see more account-takeover pressure and have added reason to steer higher-risk users toward stronger verification methods; earlier Android spyware was also reported stealing 2FA SMS codes.
- Mobile-security vendors, app distributors, and messaging platforms will need to correlate malware indicators with bot activity, rather than treating malicious apps and messaging abuse as separate detection problems.
Third-order effects
- If campaigns continue to combine broad Android targeting with commodity messaging automation, mobile fraud operations can become more distributed and resilient, raising the value of cross-platform abuse reporting and infrastructure takedowns.
- The pattern reinforces a longer-term shift away from SMS as a standalone trust signal: its usefulness for reach remains, but compromise of the device increasingly undermines it as an authentication factor.
The trend: Mobile malware is increasingly pairing Android access with messaging-platform automation to industrialize credential and account-theft operations across borders.