Here is How Analysts Use Telegram API to Intercept Data Exfiltrated by Malware
ID: 3ef0ed22-6f4a-50c5-b280-b9ce170bae4d
STIX ID: report--3ef0ed22-6f4a-50c5-b280-b9ce170bae4d
Feed Name: cybersecurityNews.com
Threat Score
ANY.RUN researchers demonstrate how malware leverages Telegram (and similar apps) to exfiltrate data by capturing API POST requests in a sandbox, extracting bot tokens and chat_id values, checking/removing webhooks, and using the /forwardMessage method to copy attacker-sent messages; the article includes sandbox-derived JSON responses and IOCs and highlights ANY.RUN features for interactive malware analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
