<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck" -->

---
title: Zero-Day &#x27;EvilVideo&#x27; Exploit in Telegram for Android...
description: A significant security flaw named &#x27;EvilVideo&#x27; was found in the Android version of the Telegram app, which allowed attackers to disguise malicious APK files as...
canonical: https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Zero-Day &#x27;EvilVideo&#x27; Exploit in Telegram for Android Patched After Five Weeks | daily.dev
og:description: A significant security flaw named &#x27;EvilVideo&#x27; was found in the Android version of the Telegram app, which allowed attackers to disguise malicious APK files as...
og:url: https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck
og:image: https://api.daily.dev/og/posts/1Hycy1KCK.png
og:image:alt: Zero-Day &#x27;EvilVideo&#x27; Exploit in Telegram for Android Patched After Five Weeks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Zero-Day 'EvilVideo' Exploit in Telegram for Android Patched After Five Weeks

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A significant security flaw named 'EvilVideo' was found in the Android version of the Telegram app, which allowed attackers to disguise malicious APK files as video files. This exploit was actively sold on hacking forums and posed serious risks to users with media auto-download enabled. Detected by ESET Research, the issue was patched in version 10.14.5 after five weeks. Users should update to the latest version for security. The incident also sheds light on other malware distribution tactics such as using games or evasion techniques like 'BadPack'.

## Content

A serious security flaw, dubbed 'EvilVideo,' was recently discovered in the Android version of the Telegram messaging app. This vulnerability allowed attackers to disguise malicious APK files as legitimate video files, posing a significant threat to users. The exploit, affecting Telegram versions 10.14.4 and older, was actively being sold on hacking forums and allowed malicious payloads to be automatically downloaded if a user had media auto-download enabled in their Telegram settings.

The exploit was first identified by cybersecurity firm ESET Research, who reported the issue to Telegram. The company took action and patched the flaw after five weeks, releasing a fix in version 10.14.5 of the app. Users are strongly advised to update to the latest version to protect themselves from potential attacks.

In addition to exploiting this flaw in Telegram, cybercriminals have also been using the popular Telegram-based game 'Hamster Kombat' to distribute other types of malware, including Ratel and Lumma Stealer. These incidents highlight the increasing sophistication of attackers leveraging popular platforms and applications to spread malware.

Furthermore, research has documented another Android malware evasion technique called 'BadPack,' which involves altering ZIP header information to avoid detection. This underscores the continuous evolution of malware tactics and the importance of keeping software updated to mitigate security risks.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#android](https://daily.dev/tags/android), [#telegram](https://daily.dev/tags/telegram)

[View this post on daily.dev](https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Zero-Day 'EvilVideo' Exploit in Telegram for Android Patched After Five Weeks","url":"https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck"},"datePublished":"2024-07-23T16:25:31.324Z","dateModified":"2024-07-24T13:11:27.062Z","description":"A significant security flaw named 'EvilVideo' was found in the Android version of the Telegram app, which allowed attackers to disguise malicious APK files as...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/edd4b64aadb0e4f626c50ab2a051d3a5?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/edd4b64aadb0e4f626c50ab2a051d3a5?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/zero-day-evilvideo-exploit-in-telegram-for-android-patched-after-five-weeks-1hycy1kck","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,android,telegram","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Zero-Day 'EvilVideo' Exploit in Telegram for Android Patched After Five Weeks"}]}
```

