TECHNOLOGY
Kaspersky Lab researchers have uncovered cyber attacks being carried out by a new piece of malware using a zero-day vulnerability feature in the Telegram Desktop app.
Kaspersky Lab researchers have uncovered cyber attacks being carried out by a new piece of malware using a zero-day vulnerability feature in the Telegram Desktop app.
The vulnerability, Kaspersky said, is being used to deliver multipurpose malware, which, depending on the computer, can be used either as a backdoor or as a tool to deliver mining software. According to the research, the vulnerability has been actively exploited since March 2017 for the cryptocurrency mining functionality, including Monero, Zcash, and others.
Social messaging services have long been an essential part of our connected life, designed to make it much easier to keep in touch with friends and family. At the same time, they can significantly complicate things if they suffer a cyberattack.
According to the research, the Telegram zero-day vulnerability was based on the RLO (right-to-left override) Unicode method. It is generally used for coding languages that are written from right to left, like Arabic or Hebrew. Besides that, however, it can also be used by malware creators to mislead users into downloading malicious files disguised, for example, as images.
Attackers used a hidden Unicode character in the file name that reversed the order of the characters, thus renaming the file itself. As a result, users downloaded hidden malware which was then installed on their computers. Kaspersky Lab reported the vulnerability to Telegram and, at the time of publication, the zero-day flaw has not since been observed in messenger's products.
During their analysis, experts identified several scenarios of zero-day exploitation in the wild by threat actors. Firstly, the vulnerability was exploited to deliver mining malware, which can be significantly harmful to users. By using the victim's PC computing power, cybercriminals have been creating different types of cryptocurrency including Monero, Zcash, Fantomcoin and others. Moreover, while analysing a threat actor's servers, Kaspersky Lab researchers found archives containing a Telegram local cache that had been stolen from victims.
Secondly, upon successful exploitation of the vulnerability, a backdoor that used the Telegram API as a command and control protocol was installed, resulting in the hackers gaining remote access to the victim's computer. After installation, it started to operate in a silent mode, which allowed the threat actor to remain unnoticed in the network and execute different commands including the further installation of spyware tools.
The artefacts discovered during the research indicate Russian origins of cybercriminals.
"The popularity of instant messenger services is incredibly high, and it's extremely important that developers provide proper protection for their users so that they don't become easy targets for criminals. We have found several scenarios of this zero-day exploitation that, besides general malware and spyware, was used to deliver mining software - such infections have become a global trend that we have seen throughout the last year. Furthermore, we believe there were other ways to abuse this zero-day vulnerability." said Alexey Firsh, Malware Analyst, Targeted Attacks Research, Kaspersky Lab.
In the wake of such attacks, Kaspersky recommends users to avoid downloading or opening files from unknown sources, and sharing any sensitive personal information via instant messengers.
Aircraft crashes in Gujarat, trainee pilot killed, details here...
Sweet moment between Virat Kohli and Preity Zinta goes viral, RCB star shows pics of..., they are...
Meet Harshita Goyal, who started as a CA, now secured AIR 2 in UPSC Civil Services 2024 Final
Meet Shakti Dubey who secured AIR 1 in UPSC Civil Services 2024 Final, she is from...
UPSC CSE Final Result 2024 DECLARED at upsc.gov.in, Shakti Dubey secures AIR 1
UPSC Civil Services 2024 Final Result Out: Shakti Dubey secures AIR 1, check full toppers list
J-K Landslide: Jammu-Srinagar national highway to be partially restored from Wednesday
TS Inter Results 2025: Telangana 1st, 2nd year result out, stepwise guide to download score card
Pope Francis death: These are 4 Indian cardinals eligible to vote for new Pope, their names are...
Bad news for Harsha Bhogle as he gets banned from this iconic venue due to...
Neeraj Chopra invites Pakistan's Arshad Nadeem to India for first-ever..., event to take place at...
Saiyaara: Ahaan Panday's debut film finally gets a release date, to hit theatres on this date
Bad news for millions of Indian mobile phone users as Mukesh Ambani, Sunil Mittal plan to...
Viral video: Aishwarya Rai grooves to Rekha, Amitabh Bachchan's iconic song Pardesiya
Bad news for Rajasthan Royals in middle of IPL 2025 as this star batter..., his name is...
Earth Day 2025: Call for renewable energy, know theme, significance, history and wishes
Do you know PM Modi had a special gift for JD Vance's children?
US VP JD Vance arrives at PM Modi's official residence, set to begin bilateral talks
Is Pakistan committing 'daily' and 'systematic' crimes in Balochistan?
Why there will be no India-US deal during JD Vance's visit? What is Donald Trump's main intention?
Full emergency declared at Delhi airport for Saudia flight SV 758, all passengers safe
UPSC Civil Services Final Result 2024 to be out soon: Where, how to check CSE results
US VP JD Vance hails Akshardham temple for its warm hospitality, kindness: 'Our kids loved it'
The beautiful love story of Zomato CEO Deepinder Goyal, Gia Goyal: 'A friend had told me...'
Waqf (Amendment) Bill, 2025: A new beginning!
Bad News for Shardul Thakur, Avesh Khan as they get removed from...
JD Vance’s India Visit: Navigating trade, tariffs, and global tensions
The Future of AI Voicebots: Multilingual support and emotion detection
THIS Mughal emperor drank only Gangajal, other emperors too preferred it due to...
Wife, daughter of former Karnataka DGP detained after his murder: 'I have killed the monster'
Land record portals in India : AnyRoR, Patta Chitta, and Bhumi online