logo

Fake Telegram Download Site Delivers Stealthy In-Memory Malware Loader

ID: 3e095b4a-ec2f-5c33-a9d7-15e33233c50d

STIX ID: report--3e095b4a-ec2f-5c33-a9d7-15e33233c50d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A typosquatting-based malware campaign distributes a trojanized Telegram installer (tsetup-x64.6.exe) that drops a malicious DLL (AutoRecoverDat.dll) and a legitimate Telegram installer as a decoy. The malware adds Windows Defender exclusions, creates registry markers, reconstructs and executes a PE payload in memory via reflective loading under rundll32.exe, and maintains persistent C2 connectivity (27.50.59.77:18852 / jiijua.com) with an update mechanism; IOCs including MD5 hashes are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.