Weaponizing Telegram Bots: How Threat Actors Exfiltrate Credentials
ID: 9335a4db-f327-5f3e-9eff-abdd5acbda4e
STIX ID: report--9335a4db-f327-5f3e-9eff-abdd5acbda4e
Feed Name: Cofense Blog
This Cofense intelligence brief explains how threat actors weaponize Telegram bot accounts and the Telegram Bot API as lightweight C2 and exfiltration channels, showing concrete examples from credential-phishing pages and malware families (Agent Tesla, WSH RAT, Pure Logs Stealer). The report includes POST request/response examples, prevalence statistics, and investigative/mitigation guidance (blocking api.telegram.org/bot endpoints, user training), and highlights how exposed bot tokens and chat IDs enable analysts to retrieve historical bot messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
