logo

[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)

ID: a68247a2-fe25-589c-a493-1eb2df3f71d9

STIX ID: report--a68247a2-fe25-589c-a493-1eb2df3f71d9

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

...
...

This report describes a honeypot compromise in which an attacker gained SSH access, performed system reconnaissance and miner-detection, and sought Telegram Desktop 'tdata' session files to steal persistent authentication tokens (enabling account takeover and bypassing 2FA). The analysis maps observed commands to an attack chain, explains how copied tdata grants immediate access on another machine, and recommends mitigations including SSH hardening, file integrity monitoring, session audits, and network detection of Telegram-related exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.