Fake Telegram Download Site Delivers Stealthy In-Memory Malware Loader
ID: 3e095b4a-ec2f-5c33-a9d7-15e33233c50d
STIX ID: report--3e095b4a-ec2f-5c33-a9d7-15e33233c50d
Feed Name: GBHackers
A typosquatting-based malware campaign distributes a trojanized Telegram installer (tsetup-x64.6.exe) that drops a malicious DLL (AutoRecoverDat.dll) and a legitimate Telegram installer as a decoy. The malware adds Windows Defender exclusions, creates registry markers, reconstructs and executes a PE payload in memory via reflective loading under rundll32.exe, and maintains persistent C2 connectivity (27.50.59.77:18852 / jiijua.com) with an update mechanism; IOCs including MD5 hashes are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
