TF-MAL-ps1.unidentified_005
📛 Threat Title
Malware family: Unidentified PS 005 (Telegram Bot)
Description
ThreatFox malware family `ps1.unidentified_005`. Printable name: Unidentified PS 005 (Telegram Bot).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Discover how to intercept data stolen by cybercriminals via Telegram bots and learn to use it to clarify related threat landscape.
-
web:anyrun.substack.com
Often, malware uses platforms like — Telegram and Discord for data exfiltration. Due to its simplicity and the lack of need for building a server architecture, this exfiltration method has gained significant popularity.
-
web:blog.nviso.eu
Adversaries utilizing popular messaging apps throughout different attack phases is nothing new. Telegram , in particular, has constantly been the subject of abuse by multiple threat actors, favoured for its anonymity, accessibility, resilience, and operational advantages. In this blog, we explore popular Telegram Bot APIs, recent campaigns involving Telegram abuse, and provide detection and ...
-
web:cybersecuritynews.com
Extracting Data Exfiltrated by Malware After acquiring the attacker's chat_id and bot token, the analysts initiated the process of checking whether the bot has a webhook. If a webhook is present, it's crucial to save its data and then delete it using the /deleteWebhook method. Once the webhook is handled, the analysts created a Telegram group and added a bot to it.
-
web:gbhackers.com
The attack leveraged a professionally crafted fake login page to harvest user credentials, employing Telegram's Bot API as a covert exfiltration channel. This method, while not entirely novel, demonstrated a high level of sophistication in mimicking legitimate government interfaces, making it particularly deceptive for unsuspecting users.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Unidentified PS 005 (Telegram Bot) malware family including references, samples and yara signatures.
-
web:medium.com
Although this analysis session wasn't attributed to any known malware family or threat actor group, the analysis revealed that Telegram bots were being used for data exfiltration.
-
web:rewterz.com
The stolen data, including usernames, IP addresses, and Windows Security Identifiers, is packaged into a ZIP archive and sent to an attacker-controlled Telegram bot . This choice of Telegram aligns with a growing trend of cybercriminals exploiting legitimate platforms for malicious activities due to their anonymity and ease of use.
-
web:www.cyfirma.com
The operational model involves not only malware development but also distribution, customer support, and monetization through subscription-based services. Telegram bots are leveraged for customer engagement, technical assistance, and payment facilitation, further reinforcing the structured nature of these criminal enterprises.
-
web:www.thaicert.or.th
66/68 Tuesday, February 18, 2025 Security researchers from Netskope Threat Labs have discovered a new backdoor malware written in Golang, which uses the Telegram Bot API as a communication channel between attackers and the malware . This allows attackers to easily send commands and receive data directly through Telegram chats.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.