logo

Analyzing Iranian Tradecraft: Leveraging Loader Scripts and Telegram for C2

ID: 6fc13811-f834-5c14-bceb-fb212f541d27

STIX ID: report--6fc13811-f834-5c14-bceb-fb212f541d27

Feed Name: Pulsedive Blog

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-06-04

Author: Pulsedive Threat Research

...
...

This report analyzes a set of loader scripts and a payload linked to intrusions that use Telegram bots for command-and-control and exfiltration, describing PowerShell/VBScript loaders that retrieve a zip containing smqdservice.exe and Python modules; it includes sample hashes, IOCs, TTP mapping to MITRE ATT&CK, and recommended mitigations for detection and prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.