TF-MAL-apk.telerat
📛 Threat Title
Malware family: TeleRAT
Description
ThreatFox malware family `apk.telerat`. Printable name: TeleRAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.telerat
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.telerat
IOC database
- Type
- domain
- Value
apk.telerat- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.telerat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.telerat
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:securityaffairs.com
TeleRAT appears to be originating from and/or to be targeting individuals in Iran, experts found similarities with another Android malware dubbed IRRAT Trojan, which also leverages Telegram's bot API for C&C communication communications. "Telegram Bots are special accounts that do not require an additional phone number to setup and are generally used to enrich Telegram chats with content ...
-
web:unit42.paloaltonetworks.com
While malware leveraging the Telegram bot API is not necessarily new, we were able to identify a new family , TeleRAT , hiding entirely behind Telegram's API to evade network-based detection and exfiltrate data.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.linkedin.com
124% surge in IoT malware attacks in 2026. That's not a gradual increase. It's an explosion. IoT malware attacks more than doubled year-over-year, with attackers recruiting millions of vulnerable ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
In 2025 and early 2026, law enforcement and cybersecurity agencies in the United States have sounded repeated alarms over the rise of sophisticated ATM "jackpotting" attacks, incidents in which threat actors use malware and physical access to force automated teller machines to dispense cash illegally. The phenomenon has cost financial institutions tens of millions of dollars and prompted an ...
-
web:www.researchgate.net
tify a specific malware family , predictive algorithms can be configured to monitor for behaviors consistent with that malware in hospital networks [22]. Th eat intelligence platforms (TIPs ...
-
web:www.securityweek.com
A newly discovered Android Trojan is abusing Telegram's Bot API to communicate with the command and control (C&C) server and to exfiltrate data, Palo Alto Networks security researchers warn. Dubbed TeleRAT , the malware appears to be originating from and/or to be targeting individuals in Iran. The threat is similar to the previously observed IRRAT Trojan, which uses Telegram's bot API for C ...
-
web:www.wilderssecurity.com
Investigating what at first seemed like increased activity on the part of the previously reported IRRAT and TeleRAT , we identified an entirely new malware family that has been spreading since at least August 2017. In March 2018, its source code was made available for free on Telegram hacking channels, and as a result, hundreds of parallel variants of the malware have been circulating in the wild.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.