logo

Telegram captcha tricks you into running malicious PowerShell scripts

ID: 28306861-2077-54db-b2e0-5da6abfb9b98

STIX ID: report--28306861-2077-54db-b2e0-5da6abfb9b98

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors exploited news about Ross Ulbricht to promote malicious Telegram channels that present a fake 'Safeguard' verification; a Telegram mini app copies a PowerShell command to victims' clipboards and instructs them to paste and run it, which downloads a ZIP (from http://openline.cyou) containing files including identity-helper.exe — a suspected Cobalt Strike loader — enabling remote access and potential follow-on ransomware or data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.