logo

The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware

ID: 21721714-278c-51db-8f98-388ccca9f601

STIX ID: report--21721714-278c-51db-8f98-388ccca9f601

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers discovered a typosquatted site (telegrgam.com) distributing a malicious installer (tsetup-x64.6.exe) that mimics the Telegram download portal; the installer deploys a DLL (AutoRecoverDat.dll) and XML-encoded payload which is reflectively loaded into memory, adds all drive partitions to Windows Defender exclusions, creates a registry persistence marker (HKCU\\MicrosoftUser\\Source), and establishes C2 communications with jiijua.com to enable remote commands, data exfiltration, and payload updates. Users are advised to verify download URLs and use official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.