logo

Telegram Sessions Targeted Through Malicious PowerShell Script

ID: a15c3130-1724-584f-b79f-bf68c7a2d895

STIX ID: report--a15c3130-1724-584f-b79f-bf68c7a2d895

Feed Name: Cyber Press

Threat Score
40/100

Date Published: 2026-04-24

Date Updated: 2026-04-25

Author: Varshini

...
...

Researchers analyzed a PowerShell 'Windows Telemetry Update' script that locates Telegram Desktop session folders, collects host metadata, compresses session files to TEMP\diag.zip, and uploads them to an attacker-controlled Telegram bot; a separate web-based collector harvesting Telegram Web auth keys was also linked to the same infrastructure. The artifacts show low sophistication (plain-text bot credentials, no persistence, un-obfuscated code) and appear to be a validation/testing capability rather than a widely deployed campaign, though the capability enables account takeover if successful.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.