s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.unidentified_005

📛 Threat Title

Malware family: Unidentified PS 005 (Telegram Bot)

Category: Unidentified PS 005 (Telegram Bot) First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.unidentified_005`. Printable name: Unidentified PS 005 (Telegram Bot).

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:any.run

    Discover how to intercept data stolen by cybercriminals via Telegram bots and learn to use it to clarify related threat landscape.

  • web:anyrun.substack.com

    Often, malware uses platforms like — Telegram and Discord for data exfiltration. Due to its simplicity and the lack of need for building a server architecture, this exfiltration method has gained significant popularity.

  • web:blog.nviso.eu

    Adversaries utilizing popular messaging apps throughout different attack phases is nothing new. Telegram , in particular, has constantly been the subject of abuse by multiple threat actors, favoured for its anonymity, accessibility, resilience, and operational advantages. In this blog, we explore popular Telegram Bot APIs, recent campaigns involving Telegram abuse, and provide detection and ...

  • web:cybersecuritynews.com

    Extracting Data Exfiltrated by Malware After acquiring the attacker's chat_id and bot token, the analysts initiated the process of checking whether the bot has a webhook. If a webhook is present, it's crucial to save its data and then delete it using the /deleteWebhook method. Once the webhook is handled, the analysts created a Telegram group and added a bot to it.

  • web:gbhackers.com

    The attack leveraged a professionally crafted fake login page to harvest user credentials, employing Telegram's Bot API as a covert exfiltration channel. This method, while not entirely novel, demonstrated a high level of sophistication in mimicking legitimate government interfaces, making it particularly deceptive for unsuspecting users.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Unidentified PS 005 (Telegram Bot) malware family including references, samples and yara signatures.

  • web:medium.com

    Although this analysis session wasn't attributed to any known malware family or threat actor group, the analysis revealed that Telegram bots were being used for data exfiltration.

  • web:rewterz.com

    The stolen data, including usernames, IP addresses, and Windows Security Identifiers, is packaged into a ZIP archive and sent to an attacker-controlled Telegram bot . This choice of Telegram aligns with a growing trend of cybercriminals exploiting legitimate platforms for malicious activities due to their anonymity and ease of use.

  • web:www.cyfirma.com

    The operational model involves not only malware development but also distribution, customer support, and monetization through subscription-based services. Telegram bots are leveraged for customer engagement, technical assistance, and payment facilitation, further reinforcing the structured nature of these criminal enterprises.

  • web:www.thaicert.or.th

    66/68 Tuesday, February 18, 2025 Security researchers from Netskope Threat Labs have discovered a new backdoor malware written in Golang, which uses the Telegram Bot API as a communication channel between attackers and the malware . This allows attackers to easily send commands and receive data directly through Telegram chats.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.