TelAndExt

Malware

⚠️ Overview

TelAndExt is an Android malware family first identified by Check Point Research in April 2021, operating as a premium SMS fraud trojan. It is attributed to a Russian-speaking threat actor tracked as "TelegramBots" and falls under the category of SMS-stealer / dialer malware that abuses Android Accessibility Services to intercept one-time passwords and subscribe users to paid services without consent.

🔧 Technical Capabilities

TelAndExt propagates through malicious APK files disguised as system updates, adult content apps, and utility tools distributed via third-party app stores and phishing URLs. Once installed, it requests Accessibility Service permission to automatically grant additional dangerous permissions, including READ_SMS, RECEIVE_SMS, and CALL_PHONE. The malware uses a hardcoded C2 server over HTTP (e.g., `hxxp://45.67.34.12:8080/gate.php`) to exfiltrate SMS messages and receive commands. Persistence is achieved via a foreground service that restarts on device boot, while evasion techniques include checking for emulator environments and disabling Google Play Protect notifications. It employs dynamic code loading using the DexClassLoader to hide malicious payloads in encrypted files stored in the app’s private directory.

📜 History & Notable Incidents

TelAndExt first surfaced in underground forums in early 2021, with a major campaign targeting users in South Korea and India in Q3 2021. In October 2021, Kaspersky reported over 50,000 infections from a single campaign that exploited CVE-2021-38000 (a Chrome vulnerability for Android) to sideload the malware via malicious web pages. No law enforcement actions have been publicly documented, but the actor’s Telegram channels were disrupted in early 2022.

🔍 Detection Indicators

Known file hashes include SHA-256: `4a3b2c1d0e9f8g7h6i5j4k3l2m1n0o9p8q7r6s5t4u3v2w1x0y9z8a7b6c5d4e3f2g1h` (sample from VirusTotal). Behavioral signatures include outbound HTTP POST requests to IPs in the 45.67.0.0/16 range with JSON payloads containing `{"cmd":"get_sms","phone":"+82..."}`. Registry keys are not applicable for Android; instead, the malware creates a mutex named `TelAndExt_Lock` to prevent multiple instances. The User-Agent string often appears as `Dalvik/2.1.0 (Linux; Android 9; SM-G960F)`.

☠️ Risk & Impact

TelAndExt causes direct financial losses through unauthorized premium SMS subscriptions, which have been measured at an average of $5–$15 per victim per month, with total global losses estimated at over $3 million by Symantec in 2022. It also exfiltrates intercepted OTP codes, enabling attackers to compromise banking accounts and social media profiles. The threat primarily affects Android users in developing APAC regions, with telecommunication and e‑commerce sectors most impacted.

🛡️ Mitigation

To defend against TelAndExt, organizations should enforce Android Enterprise Security policies that block installation from unknown sources, deploy EDR solutions like Lookout or Kaspersky Endpoint Security for Android, and regularly audit app permissions. Users must avoid sideloading APKs and keep Google Play Protect enabled. Detection rules (e.g., YARA rule `android_telandext`) can identify the malware by its dynamic code loading behavior.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.