Hackers Use Pastebin-Hosted PowerShell Script to Steal Telegram Sessions
ID: 7ebadde9-1e18-5e8a-a596-ed10437c439b
STIX ID: report--7ebadde9-1e18-5e8a-a596-ed10437c439b
Feed Name: cybersecurityNews.com
A Pastebin-hosted PowerShell script disguised as a "Windows Telemetry Update" silently gathers host metadata and Telegram session files (from %APPDATA%\Telegram Desktop and Web localStorage), compresses them into diag.zip, and exfiltrates the archive to an attacker-controlled Telegram bot via the sendDocument API. Two public revisions show a debugging cycle from a broken multipart upload (v1) to a working implementation (v2); while the tool is unsophisticated and lacks persistence or automated delivery, the functional variant and a related web-based stealer sharing the same bot infrastructure present a credible risk of account takeover if executed by victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
