Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

How hackers use PowerShell scripts to steal Telegram accounts | Kaspersky official blog

0
Medium
Vulnerability
Published: 06/23/2026 (06/23/2026, 17:27:33 UTC)
Source: Kaspersky Security Blog

Description

Cybercriminals have developed a PowerShell script that hijacks Telegram for Windows sessions by stealing session data stored locally, allowing account access without passwords or verification codes. The script masquerades as a Windows telemetry update and extracts the Telegram tdata folder containing authorization keys. Although this script was found in a prototype phase with no evidence of active exploitation, it demonstrates a novel method of account hijacking. Users are advised to monitor active Telegram sessions, terminate unrecognized sessions promptly, and enhance account security with two-step verification or passkeys. Defenses also include cautious handling of downloads, email attachments, and maintaining updated software and security solutions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/23/2026, 17:51:13 UTC

Technical Analysis

The threat involves a malicious PowerShell script disguised as a Windows telemetry update that targets Telegram for Windows users. It harvests the tdata folder, which contains session authorization keys, enabling attackers to hijack Telegram accounts without needing passwords or verification codes. The script collects system information, closes Telegram to access locked files, compresses the tdata folder, and sends it to attackers via a Telegram bot. Researchers found this script on Pastebin during its prototype testing phase, with no confirmed active exploitation. The attack vector relies on social engineering or malware delivery to run the PowerShell script on victim machines. Mitigation includes user vigilance, terminating suspicious Telegram sessions, and strengthening account security settings.

Potential Impact

If successfully executed, the script allows attackers to gain unauthorized access to Telegram accounts by stealing session data, bypassing password and two-factor authentication protections. This can lead to account hijacking, enabling attackers to impersonate users, send spam or scams, and access private communications. However, there is currently no evidence of this script being used in the wild beyond testing, limiting immediate impact.

Mitigation Recommendations

No official patch is applicable as this is a malware script rather than a software vulnerability. Users should avoid running unknown PowerShell scripts and be cautious with email attachments and downloads from untrusted sources. Regularly monitor Telegram active sessions and immediately terminate any unrecognized sessions via Settings → Devices → Terminate all other sessions. Enable Telegram's two-step verification or passkeys for enhanced account security. Keep operating systems and applications updated and use reputable security software to detect and block malicious scripts. Kaspersky Premium is recommended for additional protection against such threats.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/telegram-no-password-session-stealer/56006/","fetched":true,"fetchedAt":"2026-06-23T17:51:07.516Z","wordCount":1597}

Threat ID: 6a3ac78beed863c81e66c8f2

Added to database: 06/23/2026, 17:51:07 UTC

Last enriched: 06/23/2026, 17:51:13 UTC

Last updated: 06/23/2026, 18:25:53 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses