Telegram Sessions Targeted Through Malicious PowerShell Script
ID: a15c3130-1724-584f-b79f-bf68c7a2d895
STIX ID: report--a15c3130-1724-584f-b79f-bf68c7a2d895
Feed Name: Cyber Press
Researchers analyzed a PowerShell 'Windows Telemetry Update' script that locates Telegram Desktop session folders, collects host metadata, compresses session files to TEMP\diag.zip, and uploads them to an attacker-controlled Telegram bot; a separate web-based collector harvesting Telegram Web auth keys was also linked to the same infrastructure. The artifacts show low sophistication (plain-text bot credentials, no persistence, un-obfuscated code) and appear to be a validation/testing capability rather than a widely deployed campaign, though the capability enables account takeover if successful.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
