logo

Here is How Analysts Use Telegram API to Intercept Data Exfiltrated by Malware

ID: 3ef0ed22-6f4a-50c5-b280-b9ce170bae4d

STIX ID: report--3ef0ed22-6f4a-50c5-b280-b9ce170bae4d

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2024-10-03

Date Updated: 2026-04-21

Author: Balaji N

...
...

ANY.RUN researchers demonstrate how malware leverages Telegram (and similar apps) to exfiltrate data by capturing API POST requests in a sandbox, extracting bot tokens and chat_id values, checking/removing webhooks, and using the /forwardMessage method to copy attacker-sent messages; the article includes sandbox-derived JSON responses and IOCs and highlights ANY.RUN features for interactive malware analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.