Fake Signal and Telegram apps sneak malware into thousands of Android phones — delete these right now

A spyware alert displaying on a smartphone.
(Image credit: David MG/Shutterstock)

Hackers have developed a sneaky new tactic to push malware onto your phone and snoop on your conversations. Researchers at the cybersecurity firm ESET found fake apps in the Google and Samsung app stores that posed as extensions or premium versions of the popular messaging platforms Signal and Telegram designed to steal user data. 

The malicious apps, called Signal Plus Messenger and FlyGram, could pull sensitive information from legitimate Signal and Telegram accounts, including call logs, SMS messages, locations and more, when users took certain actions.

Here's how it works: Signal and Telegram enable users to link the mobile app to their other devices, such as their desktop or one of the best tablets. These malicious apps leverage this feature to automatically connect a compromised device to the attacker's Signal, allowing them to spy on their communications while the user is none the wiser. 

Google and Samsung have removed both apps from their respective app stores, but not before they racked up thousands of downloads. Signal Plus Messenger went live on the Play Store in July 2022 and was downloaded roughly 100 times before Google took it down in April in response to a tip from ESET, according to a report from The Hacker News. An app called FlyGram received 5,000 downloads after launching on the Play Store in June 2020 before its removal the next year. 

How to protect your Android phone

That the discovery of this stealthy "auto-linking" capability has largely gone unnoticed until now is particularly concerning. If you have either Signal Plus Messenger and FlyGram downloaded on your Android phone, you should uninstall them immediately. To keep your phone safe moving forward, it's important to download only the legitimate versions of Signal and Telegram, as well as periodically check Settings > Linked Devices to make sure no unrecognized devices pop up.

This campaign marks an unprecedented attempt to snoop on some of the most popular messaging apps in the world. Both malicious apps were built on open-source code available from Signal and Telegram. Within that code, hackers stealthily wove in the espionage tool tracked as BadBazaar, a Trojan used in previous attacks targeting Uyghurs and other Turkic ethnic minorities. ESET told the outlet it suspects the China-aligned hacking group known as GREF is behind the campaign.

"BadBazaar's main purpose is to exfiltrate device information, the contact list, call logs, and the list of installed apps, and to conduct espionage on Signal messages by secretly linking the victim's Signal Plus Messenger app to the attacker's device," security researcher Lukáš Štefanko said in an interview with The Hacker News.

In a statement to Forbes this week, Signal president Meredith Whittaker said the company was "deeply concerned for anyone who trusted and downloaded this app." She praised Google for removing "this pernicious malware masquerading as Signal off their platform," and urged Samsung to follow suit, which it has since.

More from Tom's Guide

TOPICS
Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating.

Read more
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Google Play logo on an android smartphone with corner hole punch camera
At least 5 North Korean spy apps have been found on Google Play — what you need to know
Green skull on smartphone screen.
This Android banking trojan steals passwords to take over your accounts — and all it takes is a single text message
Green skull on smartphone screen.
Hackers are spreading info-stealing malware and taking over accounts using fake wedding invitations — how to stay safe
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in Mobile Apps
Google wallet app on screen
Google Wallet now lets kids to make supervised contactless payments and use digital passes — what you need to know
How to tour the Super Bowl stadium virtually with Google Maps
Google Maps glitch is purging Timeline data — what we know
Gboard app logo on mobile phone resting on a keyboard
Google Gboard redesign has already angered users — and I can see why
Waze app on iPhone in car
Forget Google Maps — Waze just got a huge upgrade that will help millions of drivers
A photo of the Apple Maps app tile displayed on an iPhone screen
Apple Maps may soon get ads, letting businesses pay to boost visibility
How to delete TikTok
TikTok confirms return to Apple and Google app stores — here’s what we know
Latest in News
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours