{"id":16679,"date":"2026-06-05T12:58:55","date_gmt":"2026-06-05T12:58:55","guid":{"rendered":"https:\/\/theandroidapk.com\/blog\/?p=16679"},"modified":"2026-06-05T12:58:59","modified_gmt":"2026-06-05T12:58:59","slug":"firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data","status":"publish","type":"post","link":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/","title":{"rendered":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">FireScam is an Android info-stealer that pretends to be &#8220;Telegram Premium.&#8221; It spreads through a fake version of RuStore \u2014 Russia&#8217;s official app store \u2014 where victims download what looks like a free premium upgrade and actually install spyware. Once it&#8217;s on the phone it grabs almost everything: texts, contacts, call logs, location, files, clipboard and every notification that pops up (one-time passcodes included). The clever, nasty part is how it phones home \u2014 it routes <a href=\"https:\/\/theandroidapk.com\/blog\/4ukey-android-cracked-patch-download\/\">stolen data<\/a> through Google&#8217;s own Firebase, so the traffic looks legitimate. If you only install apps from the Play Store and never grant Accessibility access to something claiming to be Telegram, you&#8217;re already most of the way to safe. iPhone users aren&#8217;t a target for the malware itself, though the phishing side can still bite \u2014 more on that near the end.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What FireScam Actually Is and Why It&#8217;s Clever<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most phone malware is lazy. It grabs what it can and gets caught fast. FireScam isn&#8217;t that.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s an information stealer \u2014 it&#8217;s whole job is to quietly siphon your data off the device and out to whoever&#8217;s running it. What sets it apart is the disguise and the plumbing. The disguise: it wears Telegram&#8217;s face, right down to the icon and the name, banking on the fact that you already trust that app and won&#8217;t look twice. The plumbing: instead of beaming your data to some sketchy server that a firewall would flag in a heartbeat, it pipes everything through <a href=\"https:\/\/en.wikipedia.org\/wiki\/Firebase\">Firebase<\/a>, Google&#8217;s legitimate cloud platform that thousands of real apps use every day. Your security software sees traffic going to Google. It shrugs. The data walks out the front door wearing a hi-vis jacket.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It surfaced in late 2024, first aimed at Russian-speaking users. But here&#8217;s the thing worth sitting with \u2014 none of the machinery is tied to Russia. The fake store, the fake app, the lure: all of it clones in an afternoon into any language, any region. So treating this as &#8220;a Russia problem&#8221; misses the point entirely. The blueprint travels.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"497\" src=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-1024x497.webp\" alt=\"What FireScam Actually Is and Why It's Clever\" class=\"wp-image-16681\" srcset=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-1024x497.webp 1024w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-300x146.webp 300w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-768x373.webp 768w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-1536x746.webp 1536w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-2048x995.webp 2048w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-60x29.webp 60w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">The Fake RuStore Trick: How It Reaches Your Phone<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every part of this attack leans on one decision the victim makes: installing an app from outside the official store. Take that decision away and the whole thing collapses. So that&#8217;s exactly what the attackers engineer you into doing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It starts with a website. The attackers stand up a counterfeit <a href=\"https:\/\/en.wikipedia.org\/wiki\/RuStore\">RuStore<\/a> page \u2014 RuStore being the real, government-backed Russian app marketplace \u2014 and the fake is a close enough copy that a hurried glance won&#8217;t catch it. On that page sits the bait: &#8220;Telegram Premium,&#8221; free. No subscription, no payment, all the premium features you&#8217;d normally pay for. For a lot of people that&#8217;s an easy yes and that&#8217;s the entire trick. There&#8217;s no exploit here, no clever code breaking into your phone. Just a good-looking lie and a download button.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What you actually get comes in two stages and the two-stage design is deliberate:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>The dropper<\/strong> lands first \u2014 a small APK (reported under package names like com.tg.premium). It asks for almost nothing, because asking for a lot up front is what makes people hesitate. It&#8217;s only real job is to fetch the second piece. It&#8217;ll often dress this up as a &#8220;Telegram update&#8221; or a missing component, so the next install feels routine.<\/li>\n\n\n\n<li><strong>The payload<\/strong> is the real malware (reported as com.apps.tgpremium). This is the one wearing Telegram&#8217;s icon and name. Launch it once and it gets pushy \u2014 demanding permissions and above all pushing you to switch on Accessibility access through dialogs designed to look necessary. Grant that and it does something telling: it hides it&#8217;s own icon from your app drawer. Out of sight, running in the background, digging in for the long haul.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">That icon-hiding moment is the line between &#8220;an app I installed&#8221; and &#8220;a thing I can&#8217;t see and won&#8217;t think about again.&#8221; Which is the point.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Personal Data FireScam Steals<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"516\" src=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-1024x516.webp\" alt=\"What Personal Data FireScam Steals\" class=\"wp-image-16682\" srcset=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-1024x516.webp 1024w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-300x151.webp 300w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-768x387.webp 768w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-1536x774.webp 1536w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-2048x1033.webp 2048w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-Personal-Data-FireScam-Steals-60x30.webp 60w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Short answer: nearly all of it. This isn&#8217;t a malware that&#8217;s after one specific thing \u2014 it&#8217;s after your whole digital life and it&#8217;s organised about collecting it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s what it pulls off an infected phone:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Every text message<\/strong> \u2014 incoming and stored, which means any <a href=\"https:\/\/theandroidapk.com\/blog\/download-metamask-tumble-the-must-have-tool-for-secure-crypto-transactions\/\">one-time passcode<\/a> or banking verification SMS lands straight in the attacker&#8217;s lap.<\/li>\n\n\n\n<li><strong>Your full contact list<\/strong> \u2014 every name, every number.<\/li>\n\n\n\n<li><strong>Call logs<\/strong> \u2014 who you spoke to and when.<\/li>\n\n\n\n<li><strong>Precise location<\/strong> \u2014 GPS-level, not a vague city guess.<\/li>\n\n\n\n<li><strong>Files from storage<\/strong> \u2014 it scans your photos, documents, downloads and even app database files, then uploads ones matching certain types (images, PDFs, docs, databases).<\/li>\n\n\n\n<li><strong>Clipboard contents<\/strong> \u2014 and people copy-paste exactly the things you&#8217;d least want stolen: passwords, crypto wallet addresses.<\/li>\n\n\n\n<li><strong>Every notification<\/strong> \u2014 this is the quiet killer. Even apps it can&#8217;t directly open will show you OTPs and transaction alerts in your notification shade and FireScam reads all of them.<\/li>\n\n\n\n<li><strong>A full device fingerprint<\/strong> \u2014 model, IMEI, IMSI, MAC, IP, network operator, your installed-apps list.<\/li>\n\n\n\n<li><strong>Whatever&#8217;s on screen<\/strong> \u2014 through Accessibility access it can see which app is in the foreground and capture what&#8217;s happening there.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Notice why notification interception sits at the top. You can have perfect password hygiene, two-factor on every account, the lot \u2014 and it doesn&#8217;t matter if something is reading the OTP off your lock screen the instant it arrives. That&#8217;s the door this malware walks through. Worth reading up on how <a href=\"https:\/\/source.android.com\">Android&#8217;s notification access<\/a> is meant to work, because understanding it is half of spotting when it&#8217;s being abused.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Tech Behind the Theft: Permissions, Firebase and Hiding in Plain Sight<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is where it&#8217;s worth slowing down, because once you see <em>how<\/em> the pieces fit, the protection advice later stops feeling like a random checklist and starts feeling obvious.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Permissions It Demands and What Each One Buys<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Permissions are the whole game on Android. An app can only do what you let it do \u2014 which sounds reassuring until you realise how much damage a handful of &#8220;yes&#8221; taps can authorise. FireScam asks for a stack of the dangerous ones and each maps to a specific theft:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Permission<\/strong><\/td><td><strong>What FireScam does with it<\/strong><\/td><\/tr><tr><td>RECEIVE_SMS \/ READ_SMS<\/td><td>Reads incoming and stored texts \u2014 every OTP and bank code included<\/td><\/tr><tr><td>READ_CONTACTS<\/td><td>Lifts your entire contact list<\/td><\/tr><tr><td>READ_CALL_LOG<\/td><td>Pulls your call history<\/td><\/tr><tr><td>ACCESS_FINE_LOCATION<\/td><td>Tracks you to GPS precision<\/td><\/tr><tr><td>READ \/ WRITE_EXTERNAL_STORAGE<\/td><td>Scans and uploads your files<\/td><\/tr><tr><td>BIND_ACCESSIBILITY_SERVICE<\/td><td>Watches the screen, mimics taps, scrapes credentials from other apps<\/td><\/tr><tr><td>BIND_NOTIFICATION_LISTENER_SERVICE<\/td><td>Reads every notification, OTPs and all<\/td><\/tr><tr><td>REQUEST_INSTALL_PACKAGES<\/td><td>Installs further malware modules on command<\/td><\/tr><tr><td>RECEIVE_BOOT_COMPLETED<\/td><td>Restarts itself after every reboot<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Look at the bottom two for a second. RECEIVE_BOOT_COMPLETED is how it survives a restart \u2014 switch your phone off and on and it&#8217;s right back up. REQUEST_INSTALL_PACKAGES is the scary open-ended one: it means today&#8217;s spyware can quietly become tomorrow&#8217;s something-worse, no new download from you required.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-819x1024.webp\" alt=\"The Permissions It Demands and What Each One Buys\" class=\"wp-image-16683\" srcset=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-819x1024.webp 819w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-240x300.webp 240w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-768x960.webp 768w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-60x75.webp 60w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys-480x600.webp 480w, https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/The-Permissions-It-Demands-and-What-Each-One-Buys.webp 1122w\" sizes=\"(max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">But the two that do the heavy lifting are <a href=\"https:\/\/en.wikipedia.org\/wiki\/Android_(operating_system)\">Accessibility Service<\/a> and the Notification Listener. Accessibility was built for a genuinely good reason \u2014 to let people with disabilities use their phones, by allowing trusted apps to read the screen and act on a user&#8217;s behalf. It&#8217;s a brilliant feature. It&#8217;s also a master key and malware authors know it. Hand that key to a fake Telegram and you&#8217;ve given it permission to watch everything you do and act as if it were you. No real messaging app needs it. None. If &#8220;Telegram&#8221; asks for Accessibility access, that single request is the tell \u2014 stop right there.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why Firebase Makes This So Hard to Catch<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now the part that makes FireScam genuinely sharp rather than just greedy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most malware betrays itself with it&#8217;s network traffic. It has to send the stolen data <em>somewhere<\/em> and that somewhere is usually a dodgy server on an IP that threat feeds already know about. Block the address, kill the malware. Simple.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FireScam sidesteps all of that by using a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Firebase\">Firebase Realtime Database<\/a> \u2014 Google&#8217;s own cloud product \u2014 as it&#8217;s command-and-control hub. The malware has a Firebase database address baked in and when it wants to ship your data out, it just writes to that database. To any network monitor watching, that&#8217;s a connection to Google&#8217;s cloud. Utterly normal. The same kind of traffic a thousand legitimate apps generate every minute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s roughly how the operation runs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Each infected phone registers itself under it&#8217;s own unique node in the database.<\/li>\n\n\n\n<li>Stolen data gets written into tidy buckets \u2014 one path for SMS, one for contacts and so on. Structured, organised, easy for the operator to sort through.<\/li>\n\n\n\n<li>Commands flow back the other way. The malware checks a &#8220;commands&#8221; area for instructions and does as it&#8217;s told. The operator can say upload_file (grab a specific document), get_location, update_config (switch to a new C2 address or change which file types to steal) or uninstall_self \u2014 wipe the evidence once the job&#8217;s done.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">That last command is the cold professional touch. When they&#8217;ve taken what they want, they can have the malware delete itself, leaving you with no obvious sign anything ever happened.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Tricks It Uses to Avoid Getting Caught<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FireScam also actively works to dodge the people trying to study it:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Obfuscation<\/strong> \u2014 it&#8217;s code is deliberately scrambled so analysts can&#8217;t easily read what it does.<\/li>\n\n\n\n<li><strong>Emulator detection<\/strong> \u2014 security researchers often run suspicious apps in a virtual sandbox rather than a real phone. FireScam checks whether it&#8217;s in one of those and if it thinks it is, it sits still and behaves, giving the analyst nothing to see.<\/li>\n\n\n\n<li><strong>Time delays<\/strong> \u2014 it waits a while after install before doing anything nasty, so an automated scan that runs for a couple of minutes comes back clean.<\/li>\n\n\n\n<li><strong>Icon hiding<\/strong> \u2014 the disappearing-icon move from earlier, which is as much about evading you as anything else.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Add it up and you&#8217;ve got malware built to be quiet on the wire, quiet in the sandbox and invisible in your app drawer. Which is exactly why prevention beats detection here \u2014 by the time you&#8217;d notice, it&#8217;s already had it&#8217;s hands in everything. There&#8217;s good ongoing coverage of this kind of campaign at outlets like <a href=\"https:\/\/www.bleepingcomputer.com\">BleepingComputer<\/a> and <a href=\"https:\/\/thehackernews.com\">The Hacker News<\/a> if you want to follow how it evolves.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to Protect Your Android Device Right Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Good news after all that: the defence is genuinely simple, because the entire attack hinges on a few choices you control. Shut those down and FireScam has nowhere to start.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Only install from the Google Play Store.<\/strong> This one habit defeats the whole campaign. The fake RuStore, the &#8220;free Premium&#8221; page, the click-to-install APK \u2014 none of it can touch you if sideloaded apps aren&#8217;t on the menu.<\/li>\n\n\n\n<li><strong>Turn off &#8220;install unknown apps.&#8221;<\/strong> Go through your browsers and file managers and revoke their permission to install apps. Even if you click a bad link by mistake, the install just won&#8217;t proceed.<\/li>\n\n\n\n<li><strong>Treat any Accessibility request as a red flag.<\/strong> Real messaging apps don&#8217;t need it. If something calling itself Telegram asks, that&#8217;s not a hurdle to clear \u2014 it&#8217;s the moment to back out and delete.<\/li>\n\n\n\n<li><strong>Read what you&#8217;re granting.<\/strong> A messaging app asking to read your SMS, your call log <em>and<\/em> your notifications is asking for far more than it&#8217;s job requires. Mismatch between what an app does and what it wants is the warning sign.<\/li>\n\n\n\n<li><strong>Audit your Accessibility services.<\/strong> Open <strong>Settings \u2192 Accessibility \u2192 Installed Services<\/strong> and look at what&#8217;s listed. Anything you don&#8217;t recognise or don&#8217;t remember enabling \u2014 switch it off and investigate.<\/li>\n\n\n\n<li><strong>Run a reputable mobile security app<\/strong> and keep it current, as a backstop for the things you might miss.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If you think you&#8217;ve already installed it: get offline, uninstall anything you don&#8217;t recognise (the icon may be hidden, so check <strong>Settings \u2192 Apps<\/strong> for the full list, not just the drawer), revoke Accessibility and notification access from anything suspicious and change critical passwords from a <em>different<\/em>, clean device \u2014 because the infected one may still be watching as you type. Android security communities like <a href=\"https:\/\/www.reddit.com\">r\/androidsecurity<\/a> are a decent place to sanity-check symptoms if you&#8217;re unsure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What About iPhones? A Quick Reality Check<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you&#8217;re reading this on an iPhone feeling smug, you&#8217;ve half earned it. Let&#8217;s be precise about which half.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is no iPhone version of FireScam. Not &#8220;none found yet&#8221; in the nervous sense \u2014 the malware simply can&#8217;t do on a standard iPhone what it does on Android, because the building blocks it relies on don&#8217;t exist there. A few reasons and they&#8217;re worth knowing rather than just taking on faith:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>App sandboxing.<\/strong> Every <a href=\"https:\/\/en.wikipedia.org\/wiki\/IOS\">iOS<\/a> app is sealed in it&#8217;s own box. It can&#8217;t reach into another app to read your texts, your call log or another app&#8217;s data. The cross-app rummaging that defines FireScam on Android just hits a wall.<\/li>\n\n\n\n<li><strong>No Accessibility master key.<\/strong> iOS accessibility features are far more locked down and can&#8217;t be turned into a screen-watching, SMS-reading backdoor the way Android&#8217;s can.<\/li>\n\n\n\n<li><strong>No free-roaming file access.<\/strong> An iPhone app can&#8217;t wander your file system. It only sees what you hand it through the document picker, deliberately, one thing at a time.<\/li>\n\n\n\n<li><strong>App Store review.<\/strong> An app demanding the kind of access FireScam needs wouldn&#8217;t survive Apple&#8217;s review to reach the store in the first place.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So the malware itself? Not your problem. But \u2014 and this matters \u2014 the <em>con<\/em> that delivers it absolutely still works on you, just with a smaller payoff for the attacker. The fake &#8220;Telegram Premium&#8221; page doesn&#8217;t care what phone you&#8217;re holding. On an iPhone the angles look like this:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Credential phishing.<\/strong> A fake Premium login page captures your phone number and the code it texts you and that&#8217;s enough to hijack your actual Telegram account. No malware required \u2014 you handed over the keys.<\/li>\n\n\n\n<li><strong>Enterprise-certificate apps.<\/strong> Attackers push fake apps through &#8220;click-to-install&#8221; sites using enterprise provisioning meant for internal company software. iOS will warn you with an &#8220;Untrusted Enterprise Developer&#8221; pop-up. That pop-up is the rescue \u2014 don&#8217;t tap through it.<\/li>\n\n\n\n<li><strong>TestFlight abuse.<\/strong> Some trojanised apps slip in via Apple&#8217;s beta-testing channel, usually fronting credential theft or fake-investment (&#8220;pig butchering&#8221;) scams.<\/li>\n\n\n\n<li><strong>Configuration profiles.<\/strong> A malicious device-management profile can enable real surveillance, but only if you accept an alarming list of warnings to install it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">See the common thread? Every iOS angle needs <em>you<\/em> to override a warning or type something in. The platform&#8217;s doing it&#8217;s job; the weak point is the human tapping past the alerts. So the iPhone advice is short: get Telegram from the App Store and nowhere else, never trust an enterprise-developer prompt you didn&#8217;t expect and never install a configuration profile from a random website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Stay-Safe Checklist<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u2610 Install apps from the Google Play Store (Android) or App Store (iOS) \u2014 nowhere else.<\/li>\n\n\n\n<li>\u2610 &#8220;Install unknown apps&#8221; switched off for every browser and file manager.<\/li>\n\n\n\n<li>\u2610 Never grant Accessibility access to a messaging app \u2014 that&#8217;s the single biggest red flag.<\/li>\n\n\n\n<li>\u2610 Match permissions to purpose; refuse the ones that don&#8217;t fit what the app does.<\/li>\n\n\n\n<li>\u2610 Check <strong>Settings \u2192 Accessibility \u2192 Installed Services<\/strong> now and then for anything you don&#8217;t recognise.<\/li>\n\n\n\n<li>\u2610 A &#8220;free premium&#8221; version of a paid app is bait \u2014 treat it that way.<\/li>\n\n\n\n<li>\u2610 iPhone: ignore unexpected &#8220;Untrusted Enterprise Developer&#8221; prompts and never install profiles from unknown sites.<\/li>\n\n\n\n<li>\u2610 Suspect an infection? Uninstall via <strong>Settings \u2192 Apps<\/strong>, revoke it&#8217;s access and change passwords from a clean device.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FireScam is an Android info-stealer that pretends to be &#8220;Telegram Premium.&#8221; It spreads through a fake version of RuStore \u2014 Russia&#8217;s official app store \u2014 where victims download what looks like a free premium upgrade and actually install spyware. Once it&#8217;s on the phone it grabs almost everything: texts, contacts, call logs, location, files, clipboard and every notification that pops up (one-time passcodes included). The clever, nasty part is how it phones home \u2014 it routes stolen data through Google&#8217;s own Firebase, so the traffic looks legitimate. If you only install apps from the Play Store and never grant Accessibility<\/p>\n","protected":false},"author":9,"featured_media":16680,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[1892,1886,1888,1887,1893,1891,1885,1890,1894,1889],"class_list":["post-16679","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-android-accessibility-malware","tag-android-info-stealer","tag-android-malware-protection","tag-android-spyware","tag-fake-rustore","tag-fake-telegram-premium","tag-firebase-c2-malware","tag-firescam-android","tag-firescam-malware","tag-otp-stealing-malware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK\" \/>\n<meta property=\"og:description\" content=\"FireScam is an Android info-stealer that pretends to be &#8220;Telegram Premium.&#8221; It spreads through a fake version of RuStore \u2014 Russia&#8217;s official app store \u2014 where victims download what looks like a free premium upgrade and actually install spyware. Once it&#8217;s on the phone it grabs almost everything: texts, contacts, call logs, location, files, clipboard and every notification that pops up (one-time passcodes included). The clever, nasty part is how it phones home \u2014 it routes stolen data through Google&#8217;s own Firebase, so the traffic looks legitimate. If you only install apps from the Play Store and never grant Accessibility\" \/>\n<meta property=\"og:url\" content=\"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/\" \/>\n<meta property=\"og:site_name\" content=\"AndroidAPK\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-05T12:58:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-05T12:58:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-scaled.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1244\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Dev Bug\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dev Bug\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/\"},\"author\":{\"name\":\"Dev Bug\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/#\\\/schema\\\/person\\\/3f7f04e9a67d56e8d29d906d32dd02cb\"},\"headline\":\"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data\",\"datePublished\":\"2026-06-05T12:58:55+00:00\",\"dateModified\":\"2026-06-05T12:58:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/\"},\"wordCount\":2547,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp\",\"keywords\":[\"android accessibility malware\",\"android info stealer\",\"android malware protection\",\"android spyware\",\"fake rustore\",\"fake telegram premium\",\"firebase c2 malware\",\"firescam android\",\"firescam malware\",\"otp stealing malware\"],\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/\",\"url\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/\",\"name\":\"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp\",\"datePublished\":\"2026-06-05T12:58:55+00:00\",\"dateModified\":\"2026-06-05T12:58:59+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/#\\\/schema\\\/person\\\/3f7f04e9a67d56e8d29d906d32dd02cb\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp\",\"contentUrl\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp\",\"width\":1672,\"height\":853,\"caption\":\"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/\",\"name\":\"AndroidAPK\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/theandroidapk.com\\\/blog\\\/#\\\/schema\\\/person\\\/3f7f04e9a67d56e8d29d906d32dd02cb\",\"name\":\"Dev Bug\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g\",\"caption\":\"Dev Bug\"},\"sameAs\":[\"https:\\\/\\\/theandroidapk.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/","og_locale":"en_US","og_type":"article","og_title":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK","og_description":"FireScam is an Android info-stealer that pretends to be &#8220;Telegram Premium.&#8221; It spreads through a fake version of RuStore \u2014 Russia&#8217;s official app store \u2014 where victims download what looks like a free premium upgrade and actually install spyware. Once it&#8217;s on the phone it grabs almost everything: texts, contacts, call logs, location, files, clipboard and every notification that pops up (one-time passcodes included). The clever, nasty part is how it phones home \u2014 it routes stolen data through Google&#8217;s own Firebase, so the traffic looks legitimate. If you only install apps from the Play Store and never grant Accessibility","og_url":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/","og_site_name":"AndroidAPK","article_published_time":"2026-06-05T12:58:55+00:00","article_modified_time":"2026-06-05T12:58:59+00:00","og_image":[{"width":2560,"height":1244,"url":"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/What-FireScam-Actually-Is-and-Why-Its-Clever-scaled.webp","type":"image\/webp"}],"author":"Dev Bug","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Dev Bug","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#article","isPartOf":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/"},"author":{"name":"Dev Bug","@id":"https:\/\/theandroidapk.com\/blog\/#\/schema\/person\/3f7f04e9a67d56e8d29d906d32dd02cb"},"headline":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data","datePublished":"2026-06-05T12:58:55+00:00","dateModified":"2026-06-05T12:58:59+00:00","mainEntityOfPage":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/"},"wordCount":2547,"commentCount":0,"image":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#primaryimage"},"thumbnailUrl":"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp","keywords":["android accessibility malware","android info stealer","android malware protection","android spyware","fake rustore","fake telegram premium","firebase c2 malware","firescam android","firescam malware","otp stealing malware"],"articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/","url":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/","name":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data - AndroidAPK","isPartOf":{"@id":"https:\/\/theandroidapk.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#primaryimage"},"image":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#primaryimage"},"thumbnailUrl":"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp","datePublished":"2026-06-05T12:58:55+00:00","dateModified":"2026-06-05T12:58:59+00:00","author":{"@id":"https:\/\/theandroidapk.com\/blog\/#\/schema\/person\/3f7f04e9a67d56e8d29d906d32dd02cb"},"breadcrumb":{"@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#primaryimage","url":"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp","contentUrl":"https:\/\/theandroidapk.com\/blog\/wp-content\/uploads\/2026\/06\/FireScam-Android-Malware-Disguised-as-Telegram-App-Steals-Sensitive-Data.webp","width":1672,"height":853,"caption":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data"},{"@type":"BreadcrumbList","@id":"https:\/\/theandroidapk.com\/blog\/firescam-android-malware-disguised-as-telegram-app-steals-sensitive-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/theandroidapk.com\/blog\/"},{"@type":"ListItem","position":2,"name":"FireScam Android Malware Disguised as Telegram App Steals Sensitive Data"}]},{"@type":"WebSite","@id":"https:\/\/theandroidapk.com\/blog\/#website","url":"https:\/\/theandroidapk.com\/blog\/","name":"AndroidAPK","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/theandroidapk.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/theandroidapk.com\/blog\/#\/schema\/person\/3f7f04e9a67d56e8d29d906d32dd02cb","name":"Dev Bug","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d75212a0c4d506c80492110403077561ee10572524dfe164ed416b9f7f250e0f?s=96&d=mm&r=g","caption":"Dev Bug"},"sameAs":["https:\/\/theandroidapk.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/posts\/16679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/comments?post=16679"}],"version-history":[{"count":1,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/posts\/16679\/revisions"}],"predecessor-version":[{"id":16684,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/posts\/16679\/revisions\/16684"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/media\/16680"}],"wp:attachment":[{"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/media?parent=16679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/categories?post=16679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/theandroidapk.com\/blog\/wp-json\/wp\/v2\/tags?post=16679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}