Android.Backdoor.Baohuo.1.origin was distributed by threat actors by embedding it into unofficial/modified Telegram X Android APKs hosted on third-party app catalogs and suspicious websites, rather than official app stores. Doctor Web reported roughly 58,000 infections spanning nearly 3,000 device models, including not only phones and tablets but also smart TVs and in-car systems, indicating broad opportunistic targeting via sideloaded apps.
Once installed, the backdoor enables extensive manipulation of a victim’s Telegram account, including joining/leaving channels, hiding login activity, and concealing messages to maintain persistent, covert access. The incident was highlighted alongside broader 2025 mobile threat trends reported by Doctor Web, including widespread adware/fake apps, riskware linked to app modification tooling (e.g., NP Manager), and continued activity from other Android malware families—reinforcing the operational risk of installing APKs from untrusted sources and using modified messenger clients.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
On January 15, 2026, Doctor Web published its review of mobile malware activity in 2025, disclosing technical and impact details of the Android.Backdoor.Baohuo.1.origin campaign. The report said the backdoor enabled extensive control over victims’ Telegram accounts, including manipulating channel membership and concealing activity and messages for stealthy persistence.
During 2025, modified unofficial Telegram X builds carrying Android.Backdoor.Baohuo.1.origin were distributed through third-party app catalogs and suspicious websites, primarily targeting users in Indonesia and Brazil. Doctor Web said the campaign infected more than 58,000 devices across over 3,000 Android device models, including phones, tablets, smart TVs, and in-car systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.