From IRC to Instant Messaging: The Rise of Malware Communication via Chat Platforms
ID: a476200d-28d4-5944-9a9d-dc49e21a5d6e
STIX ID: report--a476200d-28d4-5944-9a9d-dc49e21a5d6e
Feed Name: Datadog Security Labs
Datadog Security Research describes a growing trend of threat actors abusing chat platforms (Discord, Telegram, etc.) for malware C2, payload hosting, and exfiltration. The report documents malicious PyPI packages that download binaries or POST stolen data to Telegram, stagers that fetch payloads from cdn.discordapp.com, examples involving VBA Stealer, zgRAT/Agent Tesla, and a Linux cryptominer, and provides IOCs (five SHA-256 hashes) plus YARA and Suricata rules to help detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
