Moneycontrol PRO
Loans
Loans
HomeTechnologyTelegram’s 'EvilVideo' vulnerability allowed hackers to send harmful files through video chats

Telegram’s 'EvilVideo' vulnerability allowed hackers to send harmful files through video chats

The ‘Evil Video’ exploit allowed hackers to send harmful video files on the Telegram app for Android. The app developers have now released an update to fix this issue.

July 24, 2024 / 22:43 IST
Telegram

Cybersecurity researchers at ESET have discovered a zero-day vulnerability targeted by attackers in the Telegram for Android app. This could have allowed attackers to send malicious payloads disguised as legitimate video chats. This vulnerability was dubbed as EvilVideo. Telegram developers have now fixed this bug earlier this month in versions 10.14.5 and above.

ESET researcher Lukas Stefanko and his team found this exploit while accessing secret online forums. They saw a seller showing pictures and a video of how the exploit works on a public Telegram channel. The researchers then found this channel and downloaded this video file to test it. This particular vulnerability was reportedly also reported by malicious actors who were trying to sell it on the dark web.

When shared in a chat, the malicious file appears as a multimedia file, which then prompts Telegram users to download it, if the automatically download media files option is enabled. Hence, the ESET researchers feared that the payload could have been easily spread to a large number of users, by planting it to various public groups or channels.

The ESET team first found this ‘EvilVideo’ malicious file on June 26, 2024, and immediately informed about it to Telegram. However, after no action was taken by the app developers at that time, the ESET team again reported on July 4. Thankfully, the Telegram app team responded quickly, confirming they will rectify this issue.

Telegram released an update on July 11, patching the vulnerability. This update makes sure that users are no longer at risk from the ‘Evil Video’ exploit, and we also suggest Telegram users update their apps at the latest.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sandip Chakraborty
first published: Jul 24, 2024 10:42 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347