The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware
ID: 21721714-278c-51db-8f98-388ccca9f601
STIX ID: report--21721714-278c-51db-8f98-388ccca9f601
Feed Name: securityonline.info
Researchers discovered a typosquatted site (telegrgam.com) distributing a malicious installer (tsetup-x64.6.exe) that mimics the Telegram download portal; the installer deploys a DLL (AutoRecoverDat.dll) and XML-encoded payload which is reflectively loaded into memory, adds all drive partitions to Windows Defender exclusions, creates a registry persistence marker (HKCU\\MicrosoftUser\\Source), and establishes C2 communications with jiijua.com to enable remote commands, data exfiltration, and payload updates. Users are advised to verify download URLs and use official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
