logo

The Telegram Malware Ecosystem

ID: 412bebe4-459b-5627-8af9-8c2a65901b42

STIX ID: report--412bebe4-459b-5627-8af9-8c2a65901b42

Feed Name: Ransomware ISAC Blog

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-08-21

Author: [email protected] (Manuel Boll)

...
...

This report describes a large-scale intelligence collection and analysis of malware using the Telegram Bot API for exfiltration and command-and-control: 9,898 observations (9,756 unique samples) yielded 9,678 bot tokens and 6,512 destination chats, with passive Bot API enrichment revealing chat metadata, admin/creator IDs, commands, webhooks and hosted panels; clustering produced 854 operator campaigns and multiple case studies including a TonConnect crypto-drainer MaaS and a MasRep takedown service, highlighting high-impact pivots (webhooks, hosted panels) and sensitive exposures (positive chat_ids that reveal operator user_ids).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.