logo

Fake Telegram site delivering RAT aimed at Chinese Users

ID: 99306345-52c8-55fc-a7d7-d81be300acbf

STIX ID: report--99306345-52c8-55fc-a7d7-d81be300acbf

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-21

Date Updated: 2026-07-21

...
...

Cyble CRIL identified a malicious campaign distributing a fake Telegram MSI (supt.msi) that installs a Trojan by DLL sideloading a malicious mpclient.dll via a renamed Windows Defender executable; the malware loads encrypted shellcode (upgrade.xml), injects into odbcad32.exe, creates a persistent service, communicates with a C2 to download additional payloads, and performs keylogging, browser data deletion, UAC bypass and credential-theft activities — IOCs (hashes and URL) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.