The Telegram Malware Ecosystem
ID: 804463cd-a1e9-57d0-bfd1-5092dfad1b4a
STIX ID: report--804463cd-a1e9-57d0-bfd1-5092dfad1b4a
Feed Name: Ransomware ISAC Blog
**Executive summary:** This report documents a large-scale, ongoing intelligence collection and analysis of malware that uses the Telegram Bot API as a one-line exfiltration and C2 channel; the dataset (snapshot to 31 Dec 2025) contains 9,898 observations covering 9,678 unique bot tokens, 9,756 sample hashes and 6,512 destination chats, and shows commodity RATs/stealers, webhook pivots, service-oriented MaaS operations (e.g., Evi-Crypto drainer), and an account-takedown relay (MasRep), with guidance on detection, enrichment and responsible handling of live tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
