s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.telerat

📛 Threat Title

Malware family: TeleRAT

Category: TeleRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.telerat`. Printable name: TeleRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.telerat VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.telerat

IOC database

Type
domain
Value
apk.telerat
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.telerat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.telerat

References (1)

Remediations (10)

  • web:securityaffairs.com

    TeleRAT appears to be originating from and/or to be targeting individuals in Iran, experts found similarities with another Android malware dubbed IRRAT Trojan, which also leverages Telegram's bot API for C&C communication communications. "Telegram Bots are special accounts that do not require an additional phone number to setup and are generally used to enrich Telegram chats with content ...

  • web:unit42.paloaltonetworks.com

    While malware leveraging the Telegram bot API is not necessarily new, we were able to identify a new family , TeleRAT , hiding entirely behind Telegram's API to evade network-based detection and exfiltrate data.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.linkedin.com

    124% surge in IoT malware attacks in 2026. That's not a gradual increase. It's an explosion. IoT malware attacks more than doubled year-over-year, with attackers recruiting millions of vulnerable ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    In 2025 and early 2026, law enforcement and cybersecurity agencies in the United States have sounded repeated alarms over the rise of sophisticated ATM "jackpotting" attacks, incidents in which threat actors use malware and physical access to force automated teller machines to dispense cash illegally. The phenomenon has cost financial institutions tens of millions of dollars and prompted an ...

  • web:www.researchgate.net

    tify a specific malware family , predictive algorithms can be configured to monitor for behaviors consistent with that malware in hospital networks [22]. Th eat intelligence platforms (TIPs ...

  • web:www.securityweek.com

    A newly discovered Android Trojan is abusing Telegram's Bot API to communicate with the command and control (C&C) server and to exfiltrate data, Palo Alto Networks security researchers warn. Dubbed TeleRAT , the malware appears to be originating from and/or to be targeting individuals in Iran. The threat is similar to the previously observed IRRAT Trojan, which uses Telegram's bot API for C ...

  • web:www.wilderssecurity.com

    Investigating what at first seemed like increased activity on the part of the previously reported IRRAT and TeleRAT , we identified an entirely new malware family that has been spreading since at least August 2017. In March 2018, its source code was made available for free on Telegram hacking channels, and as a result, hundreds of parallel variants of the malware have been circulating in the wild.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.