logo

Hackers Exploit Pastebin PowerShell Script to Hijack Telegram Sessions

ID: 7ed2cec0-2012-5f32-a7ca-527390b1967f

STIX ID: report--7ed2cec0-2012-5f32-a7ca-527390b1967f

Feed Name: GBHackers

Threat Score
45/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Mayura Kathir

...
...

**Executive summary:** The report analyzes a Pastebin-hosted PowerShell script that steals Telegram Desktop session tdata and exfiltrates it using a hardcoded Telegram Bot API token/chat ID, alongside a related web-based Telegram stealer; the tooling appears simple and in a testing/validation phase with exposed tokens and no observed wide deployment, but it demonstrates a viable method for hijacking Telegram sessions without credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.