Threats Tagged 'telegram'
View all threats tagged with 'telegram'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'telegram'
Click on any threat for detailed analysis and mitigation recommendations
ThreatDown researchers discovered CARBONATO, a Docker botnet that exploits exposed Docker daemons on port 2375. The operation was uncovered through an unauthenticated Docker registry exposed since May 2026, revealing two parallel activities: distribution of trojanized cryptocurrency wallet applications and a botnet infrastructure. The botnet leverages Hermes Agent, an MIT-licensed open-source AI framework, modified with a custom prompt directing it to execute commands via Telegram, maintain persistence, and harvest credentials. The campaign infrastructure spans multiple hosting providers including Linode, Hetzner, and Contabo, with activity documented from October 2024 through August 2026. Join the discussion | AlienVault OTX General | 09/24/2026, 07:56:13 UTC Added: 09/24/2026, 08:03:01 UTC |
BRIDGEHEAD is a supply-chain typosquatting campaign discovered in August 2026 that distributed 40 malicious npm packages impersonating popular libraries such as chalk, axios, and lodash. These packages contained install scripts that detect Windows or Windows Subsystem for Linux (WSL) environments and download a 22MB Rust-based executable from GitHub. The payload executes entirely in memory without writing files to disk and targets cryptocurrency wallets, browser credentials, cookies, and Telegram sessions. The campaign leverages legitimate services for reconnaissance and data exfiltration, complicating detection and takedown efforts. Although the malicious npm packages were removed within 84 minutes, the GitHub-hosted payload remained active for 39 hours, and the command-and-control server continued operating. This campaign specifically targets developers using WSL by crossing from Linux environments into Windows systems. Join the discussion | AlienVault OTX General | 08/20/2026, 17:08:20 UTC Added: 08/20/2026, 23:37:24 UTC |
Vidar, a Malware-as-a-Service infostealer first identified in 2018, continues to be distributed through phishing campaigns targeting Korea in the first half of 2026. The threat actor uses phishing emails disguised as job applications and copyright infringement notices, with attachments appearing as Word documents but actually being executables. Vidar employs a Go-based packer, uses Dead Drop Resolver technique via Telegram and Steam profiles to obtain C&C addresses, and implements anti-debugging and anti-VM techniques. The infostealer exfiltrates sensitive information including browser credentials, cookies, browsing history, cryptocurrency wallet data, Discord tokens, Telegram information, Steam data, Azure credentials, and screenshots. Configuration information is downloaded in JSON format, and data collection is performed based on received flags and additional downloaded conditions. Join the discussion | AlienVault OTX General | 07/09/2026, 11:27:51 UTC Added: 07/09/2026, 13:04:37 UTC |
The Leek Likho group (also known as SkyCloak or Vortex Werewolf) was first described by researchers in 2025, when a series of targeted attacks on public sector organizations in Russia and Belarus became known. This campaign was called Operation SkyCloak. We observed the continuation of its activity during February-April 2026, and also discovered a new technique that attackers use to filter files. Join the discussion | AlienVault OTX General | 05/18/2026, 19:45:29 UTC Added: 05/18/2026, 19:51:37 UTC |
Vidar is a name most infostealer trackers know well -- an Arkei descendant that has been snatching browser credentials and crypto wallets since 2018. It usually ships as a .NET binary or a C++ PE. The v1.5 sample we pulled from Triage on May 13, 2026 is neither. It is a 7 MB Go 1.25.4 native PE with a twelve-category sandbox scoring system, dead-drop C2 via Telegram and Steam profile pages, and enough crypto primitives to make a librarian blush. Join the discussion | AlienVault OTX General | 05/18/2026, 19:03:16 UTC Added: 05/18/2026, 19:06:38 UTC |
Hydra Saiga, a suspected Kazakhstani state-sponsored threat actor, has been actively targeting government, energy, and critical infrastructure in Central Asia, Europe, and the Middle East since 2021. The group is known for using Telegram Bot API for C2 communication and employing a mix of custom implants and 'Living off the Land' techniques. Their activities align closely with Kazakhstan's geopolitical interests, particularly in water and energy sectors. The group has compromised at least 34 organizations across 8 countries, with reconnaissance extending to over 200 additional targets globally. Hydra Saiga's operations demonstrate a clear focus on water infrastructure linked to major regional rivers and gas distribution systems, reflecting strategic intelligence collection efforts. Join the discussion | AlienVault OTX General | 03/17/2026, 11:03:35 UTC Added: 03/17/2026, 11:12:29 UTC |
A sophisticated multi-stage malware campaign employs living-off-the-land techniques and in-memory payload delivery to evade security controls. The infection chain begins with a hidden batch file that executes an embedded PowerShell loader, which then injects Donut-generated shellcode into legitimate Windows processes. The final payload is a heavily obfuscated .NET framework implementing advanced anti-analysis techniques, credential harvesting, surveillance capabilities, and remote system control. Data exfiltration occurs via Discord webhooks and Telegram bots. The malware, identified as Pulsar RAT, features live chat functionality and background payload deployment, demonstrating a modern, high-evasion Windows malware operation designed for long-term access and large-scale data theft. Join the discussion | AlienVault OTX General | 01/30/2026, 09:36:38 UTC Added: 01/30/2026, 17:42:47 UTC |
RedKitten is a newly identified campaign targeting Iranian interests, first observed in January 2026. The malware uses GitHub and Google Drive for configuration and payload retrieval, and Telegram for command and control. It appears to exploit the Dey 1404 Protests in Iran, targeting organizations documenting human rights abuses. The threat actor rapidly built this campaign using AI tools, as evidenced by traces of LLM-assisted development. While attribution is not definitive, the activity aligns with Iranian state-sponsored attackers. The malware, dubbed SloppyMIO, can fetch modules, execute commands, collect files, and deploy additional malware with persistence. Join the discussion | AlienVault OTX General | 01/29/2026, 21:45:57 UTC Added: 01/30/2026, 08:12:47 UTC |
A new cluster is spreading malware through phishing attacks targeting Russia. The attack methodology involves fake pages that imitate file downloads from Telegram. The article likely details the structure of these attacks, providing insights into how the malicious actors are exploiting user trust in the popular messaging platform to deliver their payload. This emerging threat, dubbed Vortex Werewolf, appears to be a sophisticated campaign specifically targeting Russian users or entities. Join the discussion | AlienVault OTX General | 01/29/2026, 07:39:26 UTC Added: 01/29/2026, 07:50:59 UTC |
An analysis of threat clusters, dubbed UNG0801 or Operation IconCat, targeting Israeli organizations. The actors use socially engineered phishing lures in Hebrew, exploiting antivirus icon spoofing from well-known vendors like SentinelOne and Check Point. Two distinct infection chains were identified, both utilizing AV-themed decoys dropped by malicious Word and PDF documents. The first campaign deploys a PyInstaller-based implant called PYTRIC, capable of system-wide wipes and backup deletion. The second campaign uses a Rust-based implant named RUSTRIC, focusing on antivirus enumeration and system information gathering. Both campaigns share similar tactics but differ in their ultimate objectives, with the first aimed at destruction and the second at espionage. Join the discussion | AlienVault OTX General | 12/22/2025, 17:06:57 UTC Added: 12/23/2025, 09:21:49 UTC |
Showing 1 to 10 of 29 results