logo

Hackers Use Pastebin-Hosted PowerShell Script to Steal Telegram Sessions

ID: 7ebadde9-1e18-5e8a-a596-ed10437c439b

STIX ID: report--7ebadde9-1e18-5e8a-a596-ed10437c439b

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Tushar Subhra Dutta

...
...

A Pastebin-hosted PowerShell script disguised as a "Windows Telemetry Update" silently gathers host metadata and Telegram session files (from %APPDATA%\Telegram Desktop and Web localStorage), compresses them into diag.zip, and exfiltrates the archive to an attacker-controlled Telegram bot via the sendDocument API. Two public revisions show a debugging cycle from a broken multipart upload (v1) to a working implementation (v2); while the tool is unsophisticated and lacks persistence or automated delivery, the functional variant and a related web-based stealer sharing the same bot infrastructure present a credible risk of account takeover if executed by victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.