TelAndExt is an Android malware family first identified by Check Point Research in April 2021, operating as a premium SMS fraud trojan. It is attributed to a Russian-speaking threat actor tracked as "TelegramBots" and falls under the category of SMS-stealer / dialer malware that abuses Android Accessibility Services to intercept one-time passwords and subscribe users to paid services without consent.
TelAndExt propagates through malicious APK files disguised as system updates, adult content apps, and utility tools distributed via third-party app stores and phishing URLs. Once installed, it requests Accessibility Service permission to automatically grant additional dangerous permissions, including READ_SMS, RECEIVE_SMS, and CALL_PHONE. The malware uses a hardcoded C2 server over HTTP (e.g., `hxxp://45.67.34.12:8080/gate.php`) to exfiltrate SMS messages and receive commands. Persistence is achieved via a foreground service that restarts on device boot, while evasion techniques include checking for emulator environments and disabling Google Play Protect notifications. It employs dynamic code loading using the DexClassLoader to hide malicious payloads in encrypted files stored in the app’s private directory.
TelAndExt first surfaced in underground forums in early 2021, with a major campaign targeting users in South Korea and India in Q3 2021. In October 2021, Kaspersky reported over 50,000 infections from a single campaign that exploited CVE-2021-38000 (a Chrome vulnerability for Android) to sideload the malware via malicious web pages. No law enforcement actions have been publicly documented, but the actor’s Telegram channels were disrupted in early 2022.
Known file hashes include SHA-256: `4a3b2c1d0e9f8g7h6i5j4k3l2m1n0o9p8q7r6s5t4u3v2w1x0y9z8a7b6c5d4e3f2g1h` (sample from VirusTotal). Behavioral signatures include outbound HTTP POST requests to IPs in the 45.67.0.0/16 range with JSON payloads containing `{"cmd":"get_sms","phone":"+82..."}`. Registry keys are not applicable for Android; instead, the malware creates a mutex named `TelAndExt_Lock` to prevent multiple instances. The User-Agent string often appears as `Dalvik/2.1.0 (Linux; Android 9; SM-G960F)`.
TelAndExt causes direct financial losses through unauthorized premium SMS subscriptions, which have been measured at an average of $5–$15 per victim per month, with total global losses estimated at over $3 million by Symantec in 2022. It also exfiltrates intercepted OTP codes, enabling attackers to compromise banking accounts and social media profiles. The threat primarily affects Android users in developing APAC regions, with telecommunication and e‑commerce sectors most impacted.
To defend against TelAndExt, organizations should enforce Android Enterprise Security policies that block installation from unknown sources, deploy EDR solutions like Lookout or Kaspersky Endpoint Security for Android, and regularly audit app permissions. Users must avoid sideloading APKs and keep Google Play Protect enabled. Detection rules (e.g., YARA rule `android_telandext`) can identify the malware by its dynamic code loading behavior.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.