By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gun GravyGun GravyGun Gravy
Notification Show More
Font ResizerAa
  • Home
  • Latest News
  • Firearms
  • Tactical
  • Videos
Reading: This fake app clone will steal everything you type on your Android
Share
Font ResizerAa
Gun GravyGun Gravy
  • Latest News
  • Firearms
  • Tactical
  • Videos
Search
  • Home
  • Latest News
  • Firearms
  • Tactical
  • Videos
Have an existing account? Sign In
Follow US
Gun Gravy > Latest News > This fake app clone will steal everything you type on your Android
This fake app clone will steal everything you type on your Android
Latest News

This fake app clone will steal everything you type on your Android

Jim Flanders
Last updated: January 9, 2025 4:23 pm
Jim Flanders Published January 9, 2025
Share
SHARE

Fake apps are a big problem, and their clever social engineering tricks make them hard to catch. 

There are tons of these apps out there mimicking popular apps like PayPal and Spotify. Security researchers have found another fake app pretending to be the premium version of Telegram, a messaging app with over a billion downloads. Hackers are using this app to spread malware called FireScam. It can steal everything you type on your Android phone and other personal info. 

Since it tracks your keyboard, it also gets all your passwords, which could give hackers access to sensitive data.

I’M GIVING AWAY THE LATEST & GREATEST AIRPODS PRO 2

What you need to know about FireScam

As reported by threat management company Cyfirma, FireScam is a type of malware that targets Android devices to steal personal information. It works like spyware, keeping an eye on what you do on your Android phone, such as reading your notifications, messages, clipboard content and more. 

Hackers are spreading FireScam by pretending it’s a premium version of Telegram. They’ve created a fake website on GitHub that looks like RuStore (a real app store in Russia). When people visit this fake site, they’re tricked into downloading an app that looks like “Telegram Premium.” However, this app is actually a trap. Once installed, it downloads the FireScam malware onto your device and starts stealing your personal data.

To avoid detection, the app is heavily disguised using a tool called DexGuard. It asks for permissions to access your storage, check installed apps and install more software. When you open the app, it shows a fake login page that looks like Telegram’s. If you enter your details, it steals your credentials.

The stolen data is first stored in a Firebase Realtime Database, but hackers later move it to private servers. The malware also registers each compromised device with a unique ID so hackers can keep track of their victims.

Man on phone

ANDROID BANKING TROJAN EVOLVES TO EVADE DETECTION AND STRIKE GLOBALLY

FireScam can steal almost everything on your phone

According to Cyfirma’s analysis, the FireScam malware is highly effective at stealing nearly all types of data from an infected Android device. It categorizes and sends anything you type, drag and drop, copy to the clipboard or even data automatically filled by password managers or exchanged between apps directly to the hackers.

The malware also monitors device state changes, such as when the screen turns on or off, and tracks e-commerce transactions to capture financial details. Plus, it spies on messaging apps to steal conversations and monitors screen activity, uploading key events to its server for further exploitation.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

fake app

ANDROID BANKING TROJAN MASQUERADES AS GOOGLE PLAY TO STEAL YOUR DATA

6 ways to stay safe from fake apps

1. Download apps only from official stores: Always use trusted app stores like Google Play or the Apple App Store to download apps. These platforms have security measures to detect and remove fake or harmful apps. Avoid downloading apps from random websites, pop-up ads or unofficial third-party stores as these are common sources of fake apps.

2. Verify the app’s developer: Before installing an app, check who created it. Look at the developer’s name and ensure it matches the official company behind the app. Fake apps often copy the names of popular apps but use slightly altered spellings or extra characters. For example, a fake might be called “PayPaal” instead of “PayPal.”

3. Pay attention to reviews and ratings: Reviews and ratings can give you insight into an app’s authenticity. If an app has mostly negative reviews, very few downloads or generic comments like “Great app,” it could be fake. Genuine apps typically have a large number of detailed reviews over time. Be cautious of apps with five-star ratings but no specific feedback.

4. Be cautious of app permissions: Check the permissions the app requests before installing. A flashlight app, for example, shouldn’t need access to your contacts or messages. If an app is asking for permissions that don’t align with its purpose, it could be a red flag. Always deny permissions that seem excessive or unnecessary.

5. Keep your phone and apps updated: Regular updates for your operating system and apps often include important security fixes that protect your device from malware. Turning on automatic updates can ensure you always have the latest protections.

6. Use strong antivirus software: Install strong antivirus software on your Android. These tools can scan apps for malware, detect suspicious activity and block harmful downloads. Strong antivirus software provides an extra layer of defense, especially when browsing or downloading apps. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES

Kurt’s key takeaway

The FireScam malware is a powerful tool that can steal everything on your phone, and it’s tough to detect if you’re not careful. Such apps can’t be distributed through legitimate app stores like the Play Store or the App Store, so they rely on third-party stores and fake websites to spread. To stay safe, the best approach is to stick to verified app stores and avoid downloading from untrustworthy sources.

When was the last time you read through the permissions an app asked for? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com. All rights reserved.

Read the full article here

You Might Also Like

Knoxville Man Shot After Smashing Car Window, Attacking Owner with Golf Club

Screenshot-scanning malware discovered on Apple App Store in first-of-its-kind attack

Democrat politician berates police officer during traffic stop: ‘Pulling over your boss’

Billion-dollar Mexican cartel ops disrupted by Trump’s border crackdown as US issues do-not-travel warning

USAID reportedly bankrolled al Qaeda terrorist’s college tuition, unearthed records show

Share This Article
Facebook Twitter Email Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

We Recommend
Does North Dakota Accept Non-Resident Carry Permits? Here’s What We Found Out
Latest News

Does North Dakota Accept Non-Resident Carry Permits? Here’s What We Found Out

Jim Flanders Jim Flanders July 6, 2025
NFA Tax Removed but Fight Continues as ‘Big Beautiful Bill’ Heads Back to House
Homeowner Shoots Armed Intruder After Suspect’s Gun Misfires During Alleged Attack
Louisiana Man Shoots Co-Worker in Self-Defense After Co-Worker Repeatedly Strikes Him in the Head
American veterans attacked, injured while distributing aid in Gaza with US-backed group
Subway riders deliver street justice to brute who grabbed screaming woman on platform
Head of Ukraine’s Military Intelligence Says Kiev Can’t Turn The Tide In The War With Russia
Tactical

Head of Ukraine’s Military Intelligence Says Kiev Can’t Turn The Tide In The War With Russia

Jim Flanders Jim Flanders July 5, 2025
120,000 fake sites fuel Amazon Prime Day scams
Latest News

120,000 fake sites fuel Amazon Prime Day scams

Jim Flanders Jim Flanders July 5, 2025
Town Official Loses His Mind When DoorDash Driver Knocks On His Door
TacticalVideos

Town Official Loses His Mind When DoorDash Driver Knocks On His Door

Active Self Protection Active Self Protection July 5, 2025
  • Latest News
  • Videos
  • Tactical
  • Firearms
2024 © Gun Gravy. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?