Hackers Exploit Telegram for Initial Access to Corporate VPN, RDP, and Cloud Systems
ID: 8a80398b-0be3-546b-8f34-e92e80466def
STIX ID: report--8a80398b-0be3-546b-8f34-e92e80466def
Feed Name: GBHackers
Threat Score
The report documents Telegram's rise as a central operational layer for cybercrime, where stealer logs and leaked credentials are aggregated, searched, and resold to Initial Access Brokers, ransomware groups, and hacktivists; channels and bots facilitate subscription-based malware distribution, credential exfiltration, live verification of access (RDP/VPN/cloud), and victim shaming, accelerating hands‑on‑keyboard intrusions and lowering barriers for attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
