Fake Telegram site delivering RAT aimed at Chinese Users
ID: 99306345-52c8-55fc-a7d7-d81be300acbf
STIX ID: report--99306345-52c8-55fc-a7d7-d81be300acbf
Feed Name: Cyble Blog
Cyble CRIL identified a malicious campaign distributing a fake Telegram MSI (supt.msi) that installs a Trojan by DLL sideloading a malicious mpclient.dll via a renamed Windows Defender executable; the malware loads encrypted shellcode (upgrade.xml), injects into odbcad32.exe, creates a persistent service, communicates with a C2 to download additional payloads, and performs keylogging, browser data deletion, UAC bypass and credential-theft activities — IOCs (hashes and URL) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
